CVE-2026-76835Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the skip_auth_routes and skip_auth_regex allow list against the resulting path. CanTrustForwardedHeaders in pkg/apis/middleware/scope.go grants that trust when the caller's address is in the trusted proxy set, and buildTrustedProxyNetSet falls back to defaultTrustedProxyIPs, which is 0.0.0.0/0 and ::/0, whenever reverse proxy mode is enabled without trusted_proxy_ip configured. Every client is therefore treated as a trusted proxy. An unauthenticated attacker can request a protected upstream path while setting X-Forwarded-Uri to a value matching an allow-listed route, so the skip-auth decision is made against the spoofed value while the upstream receives the protected path unchanged.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-24); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-24: 3Mentions · 2026-08-25: 2Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-08-27: 1Patch / Workaround · 2026-08-25: 2Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 2Technical Details · 2026-08-27: 108-2408-2508-27
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
General
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-243
Disclosure2General1
2026-08-252
Patch2
2026-08-271
PoC1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical authentication bypass in #OAuth2-Proxy. #CVE-2026-76835 CVSS: 9.1. This trivially exploited authentication bypass allows a remote attacker to access any page without requiring authentication. More info: https://ccb.belgium.be/advisories/warning-critical-authentication-bypass-oauth2-proxy-patch-immediately #Patch #Patch #Patch

    Post summary

    The advisory highlights a critical authentication bypass in OAuth2-Proxy (CVE-2026-76835) with CVSS 9.1, confirms a patch is available, but does not provide a PoC, exploit code, or evidence of active exploitation.

    01001374
    7.2K followersView on X
  • Aretiq.AI@AretiqAI
    General

    ARETIQ Daily Vulnerability Bulletin — August 24, 2026 🔴 CRITICAL: CVE-2026-76835 (oauth2-proxy/oauth2-proxy) AAS 12.5 19 vulnerabilities — CRITICAL: 1, HIGH: 18 Full bulletin: https://aretiq.ai/bulletins/2026-08-24/

    Post summary

    The bulletin announces the CVE but supplies no technical, exploit, or mitigation details, indicating a general announcement.

    0101080
    228 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - OAuth2 Proxy authentication bypass via X-Forwarded-Uri under default trusted-proxy set (CVE-2026-76835) buildTrustedProxyNetSet defaults to 0.0.0.0/0 and ::/0 when reverse-proxy mode runs without trusted_proxy_ip, so GetRequestURI trusts a client-supplied X-Forwarded-Uri from anyone. An unauthenticated attacker requests a protected path while spoofing the header to match skip_auth_routes/skip_auth_regex. Incomplete fix for CVE-2026-40575. 👉Affected: oauth2-proxy 7.15.2–7.15.4 | No fix yet — set an explicit --trusted-proxy-ip and have the upstream proxy overwrite X-Forwarded-Uri

    Post summary

    A critical OAuth2 Proxy authentication bypass (CVE‑2026‑76835) is disclosed, with no fix yet available, but the text provides a workaround by configuring --trusted-proxy‑ip and ensuring upstream proxy rewrites X‑Forwarded‑Uri.

    0001092
    294 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #PoC #Oauth2: Disponibile Proof of Concept (PoC) per la CVE-2026-76835 Rischio: 🔴 Tipologia: 🔸 Authentication Bypass 🔗 https://www.acn.gov.it/portale/w/oauth2-poc-pubblico-per-lo-sfruttamento-di-una-vulnerabilita-con-gravita-critica- ⚠️ Importante mantenere aggiornati i sistemi https://t.co/89tVVNMNpd

    Post summary

    The tweet announces a publicly available proof of concept for CVE-2026-76835, describing an authentication bypass and linking to the PoC, while advising to keep systems updated.

    0000034
    633 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is i… https://www.cve.org/CVERecord?id=CVE-2026-76835 ----- Traducción: CVE-2026-76835 OAu… https://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑76835, indicating that OAuth2 Proxy incorrectly processes client‑supplied X‑Forwarded‑Uri headers and may allow authentication bypass.

    0000033
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is i… https://www.cve.org/CVERecord?id=CVE-2026-76835

    Post summary

    The post describes a flaw in OAuth2 Proxy where the X‑Forwarded‑Uri header can be used to bypass authentication, because the guard from CVE‑2026‑40575 is improperly honored.

    000001.5K
    58.0K followersView on X

Explore more