CVE-2026-107162: high-severity vulnerability in ExpressGateway express-gateway
Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass
Published
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6
exploitation probability
—
observed exploitation
nono source reports it
Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any valid client credentials and the identifier portion of another user's refresh token can obtain that user's access token and impersonate them against oauth2-protected APIs.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
ExpressGateway · express-gatewayRelated CVEs — ExpressGateway express-gateway
In the same product, most dangerous first.
CVE-2025-9096MEDIUMExpressGateway express-gateway REST Endpoint apps.js cross site scriptingEPSS 0.3%CVE-2025-9095MEDIUMExpressGateway express-gateway REST Endpoint users.js cross site scriptingEPSS 0.3%CVE-2026-107177HIGHExpress Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth TokensEPSS —
References
https://github.com/ExpressGateway/express-gatewayhttps://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/policies/oauth2/oauth2-server.js#L221-L247https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf80b2ed7ab9b557736/lib/services/tokens/token.service.js#L100-L136https://github.com/ExpressGateway/express-gateway/issues/1076https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-oauth-2.0-refresh-token-validation-bypass