CVE-2026-101271
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
- Published Sep 29, 2026
- CVSS 2.1 low
- 0.2% chance of exploitation in the next 30 days (EPSS)