CVE-2026-21621 is an Incorrect Authorization vulnerability in hexpm/hexpm's Elixir.HexpmWeb.API.OAuthController, affecting versions before 71c127afebb7ed7cc637eb231b98feb802d62999. It allows privilege escalation where a read-only API key, when exchanged via OAuth client_credentials, can result in a JWT with full API access due to ignored resource qualifiers. This High severity vulnerability (CVSS 7.0) enables an attacker, with a victim's read-only API key and 2FA code, to create a new, unexpiring full-access API key for write operations. There is currently no known active exploitation, publicly available exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2025-10-17, < 2026-03-05CPE matchmatch criteria | cpe:2.3:a:hex:hexpm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.