A vulnerability was found in Erlang Ecosystem Foundation oidcc_plug up to 0.4.x and classified as critical. Affected is the function Oidcc.Plug.Authorize.call/Oidcc.Plug.AuthorizationCallback.call of the file lib/oidcc/plug/authorize.ex/lib/oidcc/plug/authorization_callback.ex of the component Authorize module. Such manipulation leads to authentication bypass by capture-replay.

This vulnerability is uniquely identified as CVE-2026-66883. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.