Junglewise Threat Intelligence

CVE-2026-57807: miniOrange OAuth Single Sign On authentication bypass in OAuth Client

CVE-2026-57807 · Severity: critical · CVSS 9.8 · Published 2026-07-10

Vendors: miniOrange.

Executive brief

A critical security flaw has been identified in the miniOrange OAuth Single Sign On plugin for WordPress, which is used to allow users to log into websites using external accounts. This vulnerability allows an unauthorized person to bypass the login process and potentially take over administrative accounts by exploiting the password recovery mechanism. If exploited, an attacker could gain full control over the website, leading to data theft, site defacement, or service disruption.

Technical details

The vulnerability is classified as an Authentication Bypass Using an Alternate Path or Channel (CWE-288) within the miniOrange OAuth Single Sign On - SSO (OAuth Client) plugin for WordPress. It stems from a flaw in how the plugin handles authentication or password recovery flows, allowing an unauthenticated remote attacker to bypass standard security checks. By exploiting this alternate path, an attacker can gain unauthorized access to high-privileged accounts, including administrators. The issue affects all versions up to and including 38.5.8. At the time of the advisory, no official patch was available, though third-party mitigation rules have been released.

Affected products

  • miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) n/a through 38.5.8

Timeline

  • 2026-06-06: other: Reported by researcher Kim Dvash
  • 2026-07-09: advisory: Patchstack advisory published
  • 2026-07-10: disclosed: CVE published to NVD

References