Post cover image

June 2, 2026

CVE-2026–22752. A Valid Token Is All It Takes. Then the OAuth Layer Becomes the Attack Surface.

CVE-2026–22752 does not require an unauthenticated attacker. It requires one with a valid Initial Access Token — a bar that is lower than…

Ilias Armenakis

2 min read