CVE-2026-101149: Security Advisory 0186
Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2025.3.4Patch Security Advisory 0186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.3Patch Security Advisory 0186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1Patch Security Advisory 0186
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a user with specific high privileges. The attack is network-reachable and does not require user interaction.
What can a successful attacker do?
An authorized high-privilege user could configure an OIDC SSO provider in a way that directs requests to arbitrary destinations. The reported impact is limited to confidentiality; integrity and availability impacts are not indicated.