Two disclosed authorization flaws could let a low-privilege view into OAuth material and cross-tenant broker metadata, underscoring how messaging systems depend on disciplined boundary enforcement.