CVE-2026-44506 - Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations
Brief
CVE ID : CVE-2026-44506
Published : Sept. 3, 2026, 8:17 p. m.
- 23 minutes ago
Description : Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.
- 10 through 5.
- 6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.
- 7.
Severity: 8.2
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
