{"id":"CVE-2026-85511","published":"2026-09-18T15:17:14.217","lastModified":"2026-09-22T16:18:04.400","description":"A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.","cvssScore":4.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-290"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:70228","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:70229","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:70230","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:70277","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-85511","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483140","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}