CVE-2026-44506 Details
Description
Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.
A vulnerability exists in Medplum versions 4.1.10 prior to 5.1.7, allowing the /oauth2/register endpoint to inadvertently disclose the client_secret of preconfigured OAuth clients. This issue arises when the defaultOAuthClients server configuration includes a client_secret and a matching redirect_uri is provided. The vulnerability is limited to self-hosted Medplum deployments that enable dynamic client registration. It does not affect hosted Medplum environments or clients created through standard administrative workflows.
Users can upgrade to Medplum version 5.1.7 or later, where this vulnerability has been fixed. It is also recommended to avoid storing sensitive client secrets in the defaultOAuthClients configuration and to rotate any client secrets if exposure is suspected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/medplum/medplum/releases/tag/v5.1.7 | [email protected] | Release NotesVendor |
| https://github.com/medplum/medplum/security/advisories/GHSA-ch8p-j6cm-r7w5 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Medplum | >= 4.1.10, < 5.1.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion