CVE Explorer
CVE-2026-33494
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequences (e.g. `/public/../admin/secrets`) that resolves to a protected path after normalization, but is matched against a permissive rule because the raw, un-normalized path is used during rule evaluation. Ve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"oathkeeper","vendor":"ory","versions":[{"status":"affected","version":"< 26.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e6fc956708a90bc15846844b4b3354ac8ee7621fb6297949c21f6583147cd13 · sha256:afdd11d7683b9e1b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4e6fc956708a90bc15846844b4b3354ac8ee7621fb6297949c21f6583147cd13 · sha256:afdd11d7683b9e1b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-23","description":"CWE-23: Relative Path Traversal","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4e6fc956708a90bc15846844b4b3354ac8ee7621fb6297949c21f6583147cd13 · sha256:afdd11d7683b9e1b… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/ory/oathkeeper/commit/8e0002140491c592db41fa141dc6ad68f417e2b2","tags":["x_refsource_MISC"],"url":"https://github.com/ory/oathkeeper/commit/8e0002140491c592db41fa141dc6ad68f417e2b2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4e6fc956708a90bc15846844b4b3354ac8ee7621fb6297949c21f6583147cd13 · sha256:afdd11d7683b9e1b… · /containers/cna/references/1
{"name":"https://github.com/ory/oathkeeper/security/advisories/GHSA-p224-6x5r-fjpm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ory/oathkeeper/security/advisories/GHSA-p224-6x5r-fjpm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4e6fc956708a90bc15846844b4b3354ac8ee7621fb6297949c21f6583147cd13 · sha256:afdd11d7683b9e1b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.