In a chilling reminder of the fragility of enterprise-grade security integrations, a critical vulnerability has been uncovered in the popular "OAuth Single Sign On – SSO (OAuth Client)" plugin developed by miniOrange. This flaw, assigned the identifier CVE-2026-57807, allows unauthenticated attackers to bypass traditional login protocols and masquerade as any user—including those with full administrative […]

