CVE-2026-93354: Taskview Community Missing Authentication via OAuth Dynamic Client Registration

Published Sep 24, 2026
·
Updated

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a clientid and clientsecret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.

Affected Software

1 affected component
Taskview Taskview Community<1.56.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Taskview Community to a version that resolves this vulnerability.

    Fixed in 1.56.0

Event History

Sep 24, 2026
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Taskview Community deployments before 1.56.0 are exposed if their OAuth 2.0 Dynamic Client Registration endpoint is enabled. The endpoint is enabled by default, so default deployments are affected.

2

What does an attacker need to exploit it?

An attacker needs no authentication or existing account. They can register an OAuth client through a POST request and use an attacker-controlled redirect URI in a malicious authorization link; successful account takeover still requires a victim to interact with that link.

3

What access can a successful attacker obtain?

The attack can capture authorization codes and exchange them for access tokens with full API access to the victim's account data. This can result in account takeover and compromise of confidentiality and integrity.

4

What should be done if upgrading is not immediately possible?

Disable the OAuth 2.0 Dynamic Client Registration endpoint if possible, because it is the exposed component used to register arbitrary clients. Upgrade Taskview Community to version 1.56.0 when possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203