Skip to content
OAuth Grants Create Unmanaged Security Risks for Organizations

OAuth Grants Create Unmanaged Security Risks for Organizations

First seen 8 Oct 2026, 14:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 21:40 UTC
  • •88 average OAuth grants created per employee, 31 with data-level permissions.
  • •OAuth grants can remain valid even after user credentials are disabled.
  • •Recent Vercel breach linked to a compromised OAuth token from a third-party app.

Organizations face significant security risks due to the proliferation of OAuth grants, which create persistent access paths to sensitive data. Employees often connect third-party applications to corporate accounts, leading to an average of 88 OAuth grants per employee, with 31 grants having data-level permissions. A notable incident involved a compromised OAuth token from Context.ai, which contributed to the Vercel breach. OAuth grants do not inherit existing security controls and can remain valid even after user credentials are disabled. This situation creates a challenge for IT and security teams who struggle to manage and review these grants effectively. The lack of visibility into OAuth grants means that many organizations are unaware of the risks they pose. As SaaS breaches are projected to stem from overprivileged OAuth tokens, organizations must develop a dedicated lifecycle and access review process for these grants.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

Recent
Vercel breach linked to OAuth token
A compromised OAuth token from Context.ai allowed unauthorized access to Vercel's systems.
BleepingComputer

More articles in this cluster (4)

Following this threat?

Track Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How many OAuth grants does an average employee create?
On average, an employee creates 88 OAuth grants, with 31 of them having data-level permissions.
What incident highlighted the risks of OAuth grants?
The Vercel breach was linked to a compromised OAuth token from Context.ai, showcasing the risks associated with unmanaged OAuth grants.
What should organizations do to manage OAuth grants?
Organizations need to establish a dedicated lifecycle and access review process for managing OAuth grants effectively.