CVE-2026-29792 is a critical vulnerability affecting Feathersjs versions 5.0.0 through 5.0.41, where an unauthenticated attacker can forge an OAuth profile to obtain a valid access token for any existing user. Rated 9.8 CRITICAL, this flaw allows a remote attacker to bypass OAuth authentication with low complexity and no user interaction by sending a crafted GET request to the callback endpoint. Successful exploitation grants the attacker full control over the targeted user's account, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, organizations using affected Feathersjs versions should upgrade to 5.0.42 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.42CPE matchmatch criteria | cpe:2.3:a:feathersjs:feathers:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.