A four-year-old fix for a classic OAuth attack closed one door. Token exchange left a nearly identical one open, and CVE-2026-59208 walked right through it.
OAuth mix-up attacks and RFC 9207: The issuer check that never made it to token exchange
calendar_today
July 20, 2026
domain
workos