CVE-2026-44506

    Dashboard / Vulnerabilities / CVE-2026-44506

    CVE-2026-44506

    Published: 3 Sept 2026Last Modified: 11 Sept 2026

    Summary: Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations

    Details: Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- abdf60cb2e07296c206a1e042174cbcdca7201ca

    Affected versions

    v5.1.6
    v5.1.5
    v5.1.4
    v5.1.3
    v5.1.2
    v5.1.1
    v5.1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-44506 | CVE-DB