VDB

GCVE-110-CLOUD-2023-0006

GCVE-110-CLOUD-2023-0006
Advisory Published
Vulnetix · Advisory published December 15, 2023
A vulnerability in Google OAuth allows employees to retain indefinite access to applications like Slack and Zoom after being removed from their company's Google organization. The issue stems from the ability to create Google accounts using corporate email aliases, which can't be off-boarded by the organization. This bypasses typical account removal processes and poses a significant security risk.

Affected Products

VendorProductVersionsPlatforms
GCPOAuth, Slack, Zoom
AWSSES

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›