CVE-2026-72887 | Net::OAuth::Client up to 0.31 Token Exchange get_request_token oauth_verifier session fixiation
A vulnerability classified as critical has been found in Net::OAuth::Client up to 0.31. Impacted is the function get_request_token of the component Token Exchange. The manipulation of the argument oauth_verifier leads to session fixiation.
This vulnerability is uniquely identified as CVE-2026-72887. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More