CVE-2026-101150: Security Advisory 0186
Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2025.3.4Patch Security Advisory 0186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.3Patch Security Advisory 0186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1Patch Security Advisory 0186
Event History
Frequently Asked Questions
Can this be exploited without authentication or user interaction?
No. Exploitation requires a user with specific high privileges, and no user interaction is required.
What security impact is indicated if exploitation succeeds?
The issue can enable server-side requests to arbitrary destinations. The supplied severity vector indicates low confidentiality impact and no integrity or availability impact.
How accessible is the vulnerable attack path?
The supplied vector indicates network access and low attack complexity, but exploitation is gated by the requirement for specific high privileges.