CVE-2026-28513 | Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange
Exp
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. This vulnerability is fixed in 2.4.0.
Conclusion & alert: CVE-2026-28513 is rated Exploit Available (55.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.26%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2026-28513
Exploit prediction scoring system (EPSS) score for CVE-2026-28513
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).