{"id":"CVE-2026-101271","published":"2026-09-29T13:17:49.980","lastModified":"2026-09-29T21:28:02.477","description":"OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-613"],"vendors":[],"products":[],"references":[{"url":"https://pretix.eu/about/en/blog/20260929-release-2026-7-1/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}