CVE-2026-55221: Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden
Summary
Boruta is an authorization server (a system that manages who gets access to applications) that implements OAuth 2.0 and OpenID Connect (protocols for secure login and permission handling). Before version 0.10.0, Boruta accidentally logged sensitive tokens (secret credentials like access tokens and ID tokens) in its business event logs, allowing attackers with access to these logs to steal the tokens and impersonate users until the tokens expired or were manually revoked.
Solution / Mitigation
This issue has been patched in version 0.10.0.
Vulnerability Details
6.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
network
low
high
none
September 2, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55221
First tracked: September 2, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 95%