Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Medplum
Medplum medplum |
|
| Vendors & Products |
Medplum
Medplum medplum |
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7. | |
| Title | Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-03T19:04:47.285Z
Reserved: 2026-05-06T18:28:20.886Z
Link: CVE-2026-44506
No data.
Status : Received
Published: 2026-09-03T20:17:21.177
Modified: 2026-09-03T20:17:21.177
Link: CVE-2026-44506
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:30:10Z
