CVE-2026-57178

Description

A flaw was found in social-auth-core. The VK application backend accepts callback data without verifying its cryptographic signature when the authentication key parameter is omitted. A remote attacker can exploit this vulnerability by submitting crafted callback requests with forged identity parameters, allowing them to bypass authentication and impersonate arbitrary users.

Statement

This vulnerability is rated as having an Important severity because an unauthenticated remote attacker could forge identity attributes and impersonate arbitrary users, compromising access controls without requiring privileged credentials. Exploitation is strictly contingent on the application explicitly enabling the VK application authentication backend. In Red Hat Ansible Automation Platform environments, this third-party social authentication provider is not configured or active by default, significantly limiting the exposure of standard deployments.

Mitigation

To mitigate this vulnerability, ensure that the VK App authentication backend is disabled. If configured, remove `social_core.backends.vk.VKAppOAuth2` from the `SOCIAL_AUTH_AUTHENTICATION_BACKENDS` setting in your application configuration.

Note that disabling this backend prevents users from authenticating through the VK App provider. A restart of the application services is required for configuration changes to take effect.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.4N/A7.4
Attack VectorNetworkN/ANetwork
Attack ComplexityHighN/AHigh
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Understanding the Weakness (CWE)

Access Control,Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands

An attacker could gain access to sensitive data and possibly execute unauthorized code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.