A vulnerability has been found in Erlang Ecosystem Foundation oidcc_plug up to 0.4.9 and classified as problematic. This impacts the function Oidcc.Plug.AuthorizationCallback.call of the file lib/oidcc/plug/authorization_callback.ex of the component AuthorizationCallback. This manipulation of the argument state causes cross-site request forgery.

This vulnerability is handled as CVE-2026-66884. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.