www.nudgesecurity.com OAuth Grants Create Unmanaged Security Risks for Organizations
Article Content
- •88 average OAuth grants created per employee, 31 with data-level permissions.
- •OAuth grants can remain valid even after user credentials are disabled.
- •Recent Vercel breach linked to a compromised OAuth token from a third-party app.
Organizations face significant security risks due to the proliferation of OAuth grants, which create persistent access paths to sensitive data. Employees often connect third-party applications to corporate accounts, leading to an average of 88 OAuth grants per employee, with 31 grants having data-level permissions. A notable incident involved a compromised OAuth token from Context.ai, which contributed to the Vercel breach. OAuth grants do not inherit existing security controls and can remain valid even after user credentials are disabled. This situation creates a challenge for IT and security teams who struggle to manage and review these grants effectively. The lack of visibility into OAuth grants means that many organizations are unaware of the risks they pose. As SaaS breaches are projected to stem from overprivileged OAuth tokens, organizations must develop a dedicated lifecycle and access review process for these grants.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How many OAuth grants does an average employee create?
What incident highlighted the risks of OAuth grants?
What should organizations do to manage OAuth grants?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…