CVE-2026-42560Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the same local user.ID, instead of deriving a unique ID from the Patreon account returned by Patreon. In practice, this means all Patreon-authenticated users of an application using this library are collapsed into a single local identity. Any application that trusts token.User.ID as the stable account key can end up mixing or fully merging unrelated Patreon users, which can lead to cross-account access, privilege confusion, and subscription-state leakage. This issue has been patched in versions 1.25.2 and 2.1.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-13); latest day: 3
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01223Mentions · 2026-05-09: 2Mentions · 2026-05-11: 1Mentions · 2026-05-13: 3Mentions · 2026-06-16: 3Technical Details · 2026-05-09: 2Technical Details · 2026-05-13: 2Technical Details · 2026-06-16: 205-0905-1105-1306-16
Signal classification2 categories
Disclosure
555.6%
General
444.4%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure2
2026-05-111
General1
2026-05-133
Disclosure1General2
2026-06-163
Disclosure2General1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    General

    Lyrie's autonomous defense platforms monitor user behavior anomalies. The identity collapse in CVE-2026-42560 would manifest as: Sudden privilege escalation or cross-account data access Session token reuse across unrelated user contexts Anomalous geographic or time-based…

    Post summary

    The post outlines potential symptoms of CVE-2026-42560 but lacks evidence of exploitation, a PoC, exploit code, patch information, or a false‑positive claim.

    1000041
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR A critical OAuth identity confusion vulnerability (CVE-2026-42560, CVSS 9.1) in the widely-used auth library maps all Patreon-authenticated users to a single local user ID. Applications using vulnerable versions (1.18.0–1.25.1 or 2.0.0–2.1.1) face immediate…

    Post summary

    The snippet announces a critical OAuth identity confusion vulnerability (CVE-2026‑42560) affecting specific library versions, providing severity and affected releases, but no exploitation or mitigation details.

    1000055
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Identity Collapse: CVE-2026-42560 Turns Every Patreon User Into the Same Person. On May 9, 2026, security researchers disclosed a critical identity management flaw in the auth library's Patreon OAuth provider integration.

    Post summary

    Security researchers publicly disclosed CVE‑2026‑42560, a critical identity‑management bug in the authentication library’s Patreon OAuth integration that treats every Patreon user as identical.

    1000043
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42560 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory auth provides authentication via oauth2, direct and email.

    Post summary

    The advisory announces a new critical CVE (CVE‑2026‑42560) with detailed CVSS information but offers no PoC, exploit, mitigation, or evidence of active exploitation.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-42560 · 9.1 → 1.18.0 CVE: CVE-2026-42560 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The snippet only lists the CVE, its CVSS score and severity, with no additional context such as PoC, exploit, patch, or active exploitation.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42560-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only includes a URL and generic hashtags, offering no concrete information about the CVE’s technical details, exploitation status, or mitigation measures.

    0000026
    210 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-42560 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42560 #CVE-2026-42560 #CVE #Critical #CyberSecurity #InfoSec https://t.co/ewLg7hdo07

    Post summary

    The tweet announces CVE-2026-42560 with a 9.1 severity rating, noting it affects multiple unspecified products and provides a link to the NVD for more details.

    0000039
    157 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42560 auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every auth… https://www.cve.org/CVERecord?id=CVE-2026-42560

    Post summary

    The snippet presents a brief announcement of CVE‑2026‑42560, specifying vulnerable versions and authentication behavior, without providing PoC, exploit, or mitigation details.

    0000043
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42560 Patreon OAuth Provider Identity Collision in Auth Library Versions 1.18.0-1.25.1 and 2.0.0-2.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42560

    Post summary

    The content announces the discovery of an identity collision vulnerability in Patreon’s OAuth provider auth library versions 1.18.0–1.25.1 and 2.0.0–2.1.1, without detailing PoCs, exploits, or patches.

    0000042
    4.0K followersView on X

Explore more