# Drupal Simple OAuth/OIDC auth bypass via an alternate path

Source: https://startwithidentity.com/cves/cve-2025-12466/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Drupal's Simple OAuth / OIDC module (6.0.0-6.0.6) enforced authentication on the primary path and forgot an alternate one. Patched in 6.0.7.

## Why it matters

Alternate-path bypasses are the cousin of the OAuth2-Proxy query-string skip ([CVE-2025-54576](https://startwithidentity.com/cves/cve-2025-54576/)) and the SmarterMail KEV item ([CVE-2026-23760](https://startwithidentity.com/cves/cve-2026-23760/)). The control exists. The attacker walks around it. CMS and mail admin planes keep failing this test.

## What to do

- Update Simple OAuth to 6.0.7 or later.
- When you add a new route to an OAuth-protected Drupal app, add it to the same auth gate. Tests should hit aliases, not only the canonical path.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-12466](https://nvd.nist.gov/vuln/detail/CVE-2025-12466)
