---
id: CVE-2026-44506
title: Medplum is a developer platform that enables development of healthcare apps
summary: >-
  Medplum is a developer platform that enables development of healthcare apps.
  In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could
  return the client_secret of preconfigured OAuth clients defined via the
  defaultOAu…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-200
published: '2026-09-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:09:13.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44506'
references:
  - url: 'https://github.com/medplum/medplum/releases/tag/v5.1.7'
    label: security-advisories@github.com
  - url: 'https://github.com/medplum/medplum/security/advisories/GHSA-ch8p-j6cm-r7w5'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00352
epssPercentile: 0.26185
ingestedAt: '2026-09-09T21:22:45.566Z'
---

## Overview

Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
