CVE-2026-3432 | SimStudioAI sim up to 0.5.73 OAuth Access Token /api/auth/oauth/token credentialAccountUserId/providerId authorization
A vulnerability was found in SimStudioAI sim up to 0.5.73. It has been declared as critical. This impacts an unknown function of the file /api/auth/oauth/token of the component OAuth Access Token Handler. Such manipulation of the argument credentialAccountUserId/providerId leads to missing authorization.
This vulnerability is listed as CVE-2026-3432. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.