CVE-2026-9084 — MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecur — CVE Database · The Intelligence Room