Severity: Critical
CVSS Score: 9.8
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts