Junglewise Threat Intelligence

CVE-2026-82183: miniOrange OAuth Single Sign On authentication bypass in Steam OpenID

CVE-2026-82183 · Severity: high · CVSS 8.1 · Published 2026-09-02

Vendors: miniOrange.

Executive brief

The OAuth Single Sign On WordPress plugin allows website administrators to let users log in via Steam accounts. Due to a failure to verify Steam's identity assertion, attackers can bypass this authentication and log in as any non-administrator user or create new accounts without valid Steam credentials. This grants unauthorized access to website accounts.

Technical details

The vulnerability is an authentication bypass (CWE-287) in the Steam single sign-on flow of the OAuth Single Sign On plugin. The plugin fails to verify the identity assertion returned by Steam's OpenID endpoint, allowing an unauthenticated attacker to forge or manipulate the authentication response and impersonate arbitrary non-administrator users. The vulnerability affects versions 6.25.0 through 7.0.0 and is exploitable over the network without requiring authentication or user interaction. Attackers can gain unauthorized account access or create new accounts. The vulnerability was fixed in version 7.0.1.

Affected products

  • miniOrange OAuth Single Sign On 6.25.0 through 7.0.0

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: patched: Fixed in version 7.0.1
  • 2026-09-02: advisory

References