CVE-2026-75542
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages.
When an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries the repositories permission and the scope string begins with repository:.
Read full descriptionShow less
The organization name is never resolved against the principal, and expand_repositories_scope/3 only rewrites the literal repositories scope, so an explicit repository:<name> passes through untouched. Both CDN edges authorize repository access from the token claim without querying the database, so the minted token is read access to that organization's private packages until it expires.
This issue affects hex.pm: from 2025-10-18 before 2026-08-24.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 8.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.46%
- Percentile among all scored CVEs: 38
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement85 % - Primary impact
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Secondary impact
T1005Data from Local Systemcollection80 %
Vulnerabilidad de autorización en endpoint OAuth que permite a un atacante remoto con PR:L (clave API válida) leer paquetes privados de otras organizaciones. Requiere privilegios y acceso de red, impactando en obtención de credenciales (token válido) y lectura de datos sensibles (paquetes privados).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-863
References
- https://cna.erlef.org/cves/CVE-2026-75542.html
- https://github.com/hexpm/hexpm/commit/bf0fb9d208f0acfabf7a2f7467c8231659e322a8
- https://github.com/hexpm/hexpm/security/advisories/GHSA-rfx8-w654-8cpr
- https://osv.dev/vulnerability/EEF-CVE-2026-75542
- https://github.com/hexpm/hexpm/security/advisories/GHSA-rfx8-w654-8cpr
Raw JSON (NVD)
Show
{
"id": "CVE-2026-75542",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-75542",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-08-25T19:53:10.499908Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:hexpm:hexpm:*:*:*:*:*:*:*:*"
],
"vendor": "hexpm",
"modules": [
"'Elixir.HexpmWeb.API.OAuthController'",
"'Elixir.Hexpm.OAuth.Tokens'"
],
"product": "hexpm",
"versions": [
{
"status": "affected",
"version": "2025-10-18",
"lessThan": "2026-08-24",
"versionType": "date"
}
],
"packageName": "hex.pm",
"programFiles": [
"lib/hexpm_web/controllers/api/oauth_controller.ex",
"lib/hexpm/oauth/tokens.ex"
],
"collectionURL": "https://hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.HexpmWeb.API.OAuthController':validate_scopes_against_key/2"
},
{
"name": "'Elixir.Hexpm.OAuth.Tokens':create_for_org/6"
}
]
},
{
"cpes": [
"cpe:2.3:a:hexpm:hexpm:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/hexpm/hexpm",
"vendor": "hexpm",
"modules": [
"'Elixir.HexpmWeb.API.OAuthController'",
"'Elixir.Hexpm.OAuth.Tokens'"
],
"product": "hexpm",
"versions": [
{
"status": "affected",
"version": "71829cb6f6559bcceb1ef4e43a2fb8cdd3af654b",
"lessThan": "bf0fb9d208f0acfabf7a2f7467c8231659e322a8",
"versionType": "git"
}
],
"packageURL": "pkg:github/hexpm/hexpm",
"packageName": "hexpm/hexpm",
"programFiles": [
"lib/hexpm_web/controllers/api/oauth_controller.ex",
"lib/hexpm/oauth/tokens.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.HexpmWeb.API.OAuthController':validate_scopes_against_key/2"
},
{
"name": "'Elixir.Hexpm.OAuth.Tokens':create_for_org/6"
}
]
}
]
}
],
"published": "2026-08-24T21:17:47.373",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-75542.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/hexpm/hexpm/commit/bf0fb9d208f0acfabf7a2f7467c8231659e322a8",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/hexpm/hexpm/security/advisories/GHSA-rfx8-w654-8cpr",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-75542",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/hexpm/hexpm/security/advisories/GHSA-rfx8-w654-8cpr",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages.\n\nWhen an API key is exchanged for a token through the OAuth client_credentials grant, validate_scopes_against_key/2 in lib/hexpm_web/controllers/api/oauth_controller.ex admits a requested scope whenever the key carries the repositories permission and the scope string begins with repository:. The organization name is never resolved against the principal, and expand_repositories_scope/3 only rewrites the literal repositories scope, so an explicit repository:<name> passes through untouched. Both CDN edges authorize repository access from the token claim without querying the database, so the minted token is read access to that organization's private packages until it expires.\n\nThis issue affects hex.pm: from 2025-10-18 before 2026-08-24."
}
],
"lastModified": "2026-09-01T21:15:00.147",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}