CVE-2026-67345 HIGH

CVE-2026-67345: MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

Vendor Dromara
Product MaxKey
Weakness CWE-183
Published July 30, 2026
Last update July 31, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 31, 2026 Record updated