CVE-2026-85511
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
- Published Sep 18, 2026
- CVSS 4.2 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available