Post cover image

June 9, 2026

How I Found a Critical OAuth Misconfiguration That Led to Account Takeover

A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues chained together into a critical account…

Shafayat Ahmed Alif

6 min read