CVE-2026-101271: OAuth credentials not disabled when application is disabled
Published Sep 29, 2026
·Updated
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
Event History
Sep 29, 2026
CVE Published
via MITRE·12:03 PM
Data Sourced
via MITRE·12:03 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can a disabled OAuth application still be used with credentials issued before it was disabled?
Yes. Access tokens already bound to the disabled application remain valid until their normal lifetime expires.
2
How can I identify whether this affects my environment?
Identify OAuth applications that were manually disabled and determine whether they have access tokens that were issued before disabling and have not yet expired.