CVE-2026-40946
Oxia may accept invalid tokens allowing unauthorized access to your data.
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
An internal attacker can bypass Oxia security by reusing tokens from other services to gain unauthorized access. This puts critical business data at risk of exposure or modification and could cause major operational disruptions.