Confirms unauthenticated access to the OAuth token endpoint by sending a credential lookup request without a session. Vulnerable instances process the request, proving any user's OAuth tokens for GitHub, Google, Slack, etc. can be stolen.
Is your app exploitable through CVE-2026-3432?
Scan your domain free