CVE-2026-3432 is a critical vulnerability affecting SimStudio versions below 0.5.74. It allows unauthenticated attackers to bypass authorization checks on the /api/auth/oauth/token endpoint by providing a user ID and provider name. This enables the theft of OAuth access tokens, granting access to users' third-party service credentials. Rated 9.1 CRITICAL on CVSS, this vulnerability has a low attack complexity and requires no user interaction, leading to high confidentiality and integrity impacts. An attacker can remotely exploit this to gain unauthorized access to sensitive information. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. While community discussion is minimal, Tenable has issued an advisory, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.74CPE matchmatch criteria | cpe:2.3:a:sim:sim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026Sim Studio AI - Unauthenticated OAuth Token Theft
Mar 2, 2026