CVE-2026-85511

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

  • Published Sep 18, 2026
  • CVSS 4.2 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-85511 at the National Vulnerability Database