CVE-2026-33494 - Vulnerability Analysis
CriticalCVSS: 10.0Last Updated: March 26, 2026
ORY Oathkeeper - Authorization Bypass
Overview
ORY Oathkeeper < 26.2.0 contains an authorization bypass caused by HTTP path traversal in URL path normalization, letting attackers bypass access control by crafting path traversal sequences, exploit requires crafted URL.
Severity & Score
Impact
Attackers can bypass authorization and access protected resources, potentially exposing sensitive data or functionality.
Mitigation
Upgrade to version 26.2.0 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-33494 - Critical (10) ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker... š https://www.thehackerwire.com/vulnerability/CVE-2026-33494/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-33494
- Severity
- Critical
- CVSS Score
- 10.0
- Type
- broken_access_control
- Status
- new
- EPSS
- 4.3%
- Social Posts
- 1
CWE
- CWE-23
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N