ATLAS Landscape
AML.T0091.000

Application Access Token

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, software-as-a-service (SaaS), and AI-as-a-service(AIaaS). They are commonly used for AI services such as chatbots, LLMs, and predictive inference APIs.

Severity CVE CVSS
HIGH CVE-2025-34291 8.8
HIGH CVE-2026-41273 8.2
HIGH CVE-2026-29872 8.2
HIGH CVE-2026-25750 8.1
HIGH CVE-2026-32730 8.1
HIGH CVE-2025-0628 8.1
HIGH CVE-2024-7053 7.6
HIGH CVE-2026-32597 7.5
HIGH CVE-2026-41266 7.5
HIGH CVE-2025-65098 7.4
HIGH CVE-2026-44549 7.3
HIGH CVE-2026-44721 7.3
HIGH CVE-2025-64496 7.3
MEDIUM CVE-2025-51471 6.9
MEDIUM CVE-2026-40934 6.8
MEDIUM CVE-2024-13698 6.5
MEDIUM CVE-2025-14980 6.5
MEDIUM GHSA-q8ff-7ffm-m3r9 6.0
MEDIUM CVE-2026-27167 5.9
MEDIUM GHSA-cc4f-hjpj-g9p8 5.6
MEDIUM CVE-2026-44479 5.5
MEDIUM CVE-2025-52478 5.4
MEDIUM CVE-2026-27578 5.4
MEDIUM CVE-2024-6845 5.3
MEDIUM CVE-2026-2589 5.3
MEDIUM CVE-2026-39411 5.0
MEDIUM CVE-2025-11972 4.9
MEDIUM CVE-2026-44568 4.8
MEDIUM CVE-2026-28415 4.7
MEDIUM CVE-2026-33720 4.2
HIGH GHSA-xmxx-7p24-h892
HIGH CVE-2026-22033
CRITICAL GHSA-5mg7-485q-xm76
CRITICAL GHSA-955r-262c-33jc
HIGH CVE-2026-34511
MEDIUM GHSA-5h3f-885m-v22w
MEDIUM GHSA-whf9-3hcx-gq54
MEDIUM CVE-2026-35657
HIGH GHSA-6f7g-v4pp-r667
HIGH GHSA-r6xh-pqhr-v4xh
HIGH CVE-2026-40171
UNKNOWN CVE-2026-42235
LOW GHSA-v8qf-fr4g-28p2