CVE-2026-70556 | Hubzilla up to 11.2.1 OAuth2 Authorization Endpoint post client_id/client_secret/redirect_uri/scope cross-site request forgery
A vulnerability identified as problematic has been detected in Hubzilla up to 11.2.1. Affected by this issue is the function ZotlabsModuleAuthorize::post of the component OAuth2 Authorization Endpoint. This manipulation of the argument client_id/client_secret/redirect_uri/scope causes cross-site request forgery.
This vulnerability appears as CVE-2026-70556. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More