CWE-347
AllowedImproper Verification of Cryptographic Signature
Abstraction: Base · Status: Draft
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
1408 vulnerabilities reference this CWE, most recent first.
CVE-2026-91191 (GCVE-0-2026-91191)
Vulnerability from cvelistv5 – Published: 2026-09-29 21:04 – Updated: 2026-09-30 15:28| Vendor | Product | Version | |
|---|---|---|---|
| Lantronix | G520 Series |
Affected:
2.6.0.4R6 stable
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91191",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:03:47.430624Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:15.769Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "G520 Series",
"vendor": "Lantronix",
"versions": [
{
"status": "affected",
"version": "2.6.0.4R6 stable"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ievgen Bondarenko reported this vulnerability to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The device\u0027s update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation."
}
],
"value": "The device\u0027s update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T21:04:52.546Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528"
},
{
"url": "https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website.\u003cbr\u003e\u003cdiv\u003e\u003ca href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528\"\u003ehttps://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528\u003c/a\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\n\u003cp\u003eFor more information, see the Lantronix Vulnerability Library.\u003cbr\u003e\u003ca href=\"https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/\"\u003ehttps://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/\u003c/a\u003e\u003c/p\u003e\u003cp\u003eFor more information or technical assistance, contact Lantronix support: Support@lantronix.com\u003cbr\u003e\u003ca href=\"mailto:Support@lantronix.com\"\u003emailto:Support@lantronix.com\u003c/a\u003e\u003c/p\u003e\n\n\u003c/div\u003e"
}
],
"value": "Lantronix has addressed the reported issues with release version 2.6.0.7R6 which is available on their website.\n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528 \n\n\n\n\n\n\n\nFor more information, see the Lantronix Vulnerability Library.\n https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/ \n\n\n\nFor more information or technical assistance, contact Lantronix support: Support@lantronix.com\n mailto:Support@lantronix.com"
}
],
"source": {
"advisory": "ICSA-26-272-01",
"discovery": "EXTERNAL"
},
"title": "Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2026-91191",
"datePublished": "2026-09-29T21:04:52.546Z",
"dateReserved": "2026-09-17T19:24:31.384Z",
"dateUpdated": "2026-09-30T15:28:15.769Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-91187 (GCVE-0-2026-91187)
Vulnerability from cvelistv5 – Published: 2026-09-24 13:20 – Updated: 2026-09-24 14:47- CWE-347 - Improper Verification of Cryptographic Signature
| URL | Tags |
|---|---|
| https://github.com/dashbitco/nimble_zta/security/… | relatedvendor-advisory |
| https://cna.erlef.org/cves/CVE-2026-91187.html | related |
| https://osv.dev/vulnerability/EEF-CVE-2026-91187 | related |
| https://github.com/dashbitco/nimble_zta/commit/bc… | related |
| https://github.com/dashbitco/nimble_zta/commit/64… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| dashbit | nimble_zta |
Affected:
0.1.2 , < 0.1.3
(semver)
cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:* |
|
| dashbit | nimble_zta |
Affected:
bc004b70985ae5763901baab3a4e204047899768 , < 6458fd18a5ba41166d4973214c519e98fe05b72d
(git)
cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91187",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:43:06.738544Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:47:30.520Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.NimbleZTA.Cloudflare\u0027"
],
"packageName": "nimble_zta",
"packageURL": "pkg:hex/nimble_zta",
"product": "nimble_zta",
"programFiles": [
"lib/nimble_zta/cloudflare.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.NimbleZTA.Cloudflare\u0027:authenticate/3"
},
{
"name": "\u0027Elixir.NimbleZTA.Cloudflare\u0027:verify_token/2"
}
],
"repo": "https://github.com/dashbitco/nimble_zta",
"vendor": "dashbit",
"versions": [
{
"lessThan": "0.1.3",
"status": "affected",
"version": "0.1.2",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.NimbleZTA.Cloudflare\u0027"
],
"packageName": "dashbitco/nimble_zta",
"packageURL": "pkg:github/dashbitco/nimble_zta",
"product": "nimble_zta",
"programFiles": [
"lib/nimble_zta/cloudflare.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.NimbleZTA.Cloudflare\u0027:authenticate/3"
},
{
"name": "\u0027Elixir.NimbleZTA.Cloudflare\u0027:verify_token/2"
}
],
"repo": "https://github.com/dashbitco/nimble_zta",
"vendor": "dashbit",
"versions": [
{
"lessThan": "6458fd18a5ba41166d4973214c519e98fe05b72d",
"status": "affected",
"version": "bc004b70985ae5763901baab3a4e204047899768",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe application must add \u003ccode\u003eNimbleZTA.Cloudflare\u003c/code\u003e to its supervision tree and authenticate requests through it.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "The application must add `NimbleZTA.Cloudflare` to its supervision tree and authenticate requests through it."
}
],
"value": "The application must add NimbleZTA.Cloudflare to its supervision tree and authenticate requests through it."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.1.3",
"versionStartIncluding": "0.1.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Kazlu"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Jos\u00e9 Valim / Dashbit"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"dateAssigned": "2026-09-24T09:09:36.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eImproper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003everify_token/2\u003c/code\u003e in \u003ccode\u003elib/nimble_zta/cloudflare.ex\u003c/code\u003e matches the result of \u003ccode\u003eJOSE.JWT.verify/2\u003c/code\u003e against \u003ccode\u003e{_, token, _s}\u003c/code\u003e, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the \u003ccode\u003ecf-access-jwt-assertion\u003c/code\u003e header, carrying the expected \u003ccode\u003eiss\u003c/code\u003e claim and the seven service token claims. \u003ccode\u003everify_iss/2\u003c/code\u003e reads the \u003ccode\u003eiss\u003c/code\u003e claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity.\u003c/p\u003e\n\u003cp\u003eThis issue affects nimble_zta: from 0.1.2 before 0.1.3.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected.\n\n`verify_token/2` in `lib/nimble_zta/cloudflare.ex` matches the result of `JOSE.JWT.verify/2` against `{_, token, _s}`, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the `cf-access-jwt-assertion` header, carrying the expected `iss` claim and the seven service token claims. `verify_iss/2` reads the `iss` claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity.\n\nThis issue affects nimble_zta: from 0.1.2 before 0.1.3."
}
],
"value": "Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected.\n\nverify_token/2 in lib/nimble_zta/cloudflare.ex matches the result of JOSE.JWT.verify/2 against {_, token, _s}, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the cf-access-jwt-assertion header, carrying the expected iss claim and the seven service token claims. verify_iss/2 reads the iss claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity.\n\nThis issue affects nimble_zta: from 0.1.2 before 0.1.3."
}
],
"impacts": [
{
"capecId": "CAPEC-475",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe attacker authenticates as an arbitrary Cloudflare service token without holding the Cloudflare signing key. The application receives the \u003ccode\u003eclient_id\u003c/code\u003e and the claims of the forged token as the authenticated identity, so the attacker gets the access that the application grants to that service token.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "The attacker authenticates as an arbitrary Cloudflare service token without holding the Cloudflare signing key. The application receives the `client_id` and the claims of the forged token as the authenticated identity, so the attacker gets the access that the application grants to that service token."
}
],
"value": "The attacker authenticates as an arbitrary Cloudflare service token without holding the Cloudflare signing key. The application receives the client_id and the claims of the forged token as the authenticated identity, so the attacker gets the access that the application grants to that service token."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T13:20:52.974Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"name": "GitHub Advisory",
"tags": [
"related",
"vendor-advisory"
],
"url": "https://github.com/dashbitco/nimble_zta/security/advisories/GHSA-rj24-g8cc-g7g2"
},
{
"name": "EEF CNA record for CVE-2026-91187",
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-91187.html"
},
{
"name": "OSV record EEF-CVE-2026-91187",
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-91187"
},
{
"name": "Introducing commit bc004b7 in dashbitco/nimble_zta",
"tags": [
"related"
],
"url": "https://github.com/dashbitco/nimble_zta/commit/bc004b70985ae5763901baab3a4e204047899768"
},
{
"name": "Fix commit 6458fd1 in dashbitco/nimble_zta",
"tags": [
"patch"
],
"url": "https://github.com/dashbitco/nimble_zta/commit/6458fd18a5ba41166d4973214c519e98fe05b72d"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDisable the Cloudflare authentication strategy.\u003c/p\u003e\n\u003cp\u003eTo keep the user identity strategy available, reject the service token requests yourself. Examine each request before you call \u003ccode\u003eNimbleZTA.Cloudflare.authenticate/3\u003c/code\u003e, and reject it if its JWT carries the \u003ccode\u003ecommon_name\u003c/code\u003e claim and the \u003ccode\u003etype\u003c/code\u003e claim.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Disable the Cloudflare authentication strategy.\n\nTo keep the user identity strategy available, reject the service token requests yourself. Examine each request before you call `NimbleZTA.Cloudflare.authenticate/3`, and reject it if its JWT carries the `common_name` claim and the `type` claim."
}
],
"value": "Disable the Cloudflare authentication strategy.\n\nTo keep the user identity strategy available, reject the service token requests yourself. Examine each request before you call NimbleZTA.Cloudflare.authenticate/3, and reject it if its JWT carries the common_name claim and the type claim."
}
],
"x_proofOfConcept": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003col\u003e\n\u003cli\u003eBuild a JWT payload that carries the \u003ccode\u003eaud\u003c/code\u003e, \u003ccode\u003ecommon_name\u003c/code\u003e, \u003ccode\u003eexp\u003c/code\u003e, \u003ccode\u003eiat\u003c/code\u003e, \u003ccode\u003eiss\u003c/code\u003e, \u003ccode\u003esub\u003c/code\u003e and \u003ccode\u003etype\u003c/code\u003e claims. Use the \u003ccode\u003eiss\u003c/code\u003e the application expects, set \u003ccode\u003eexp\u003c/code\u003e to a future timestamp, and set \u003ccode\u003ecommon_name\u003c/code\u003e to the service token to impersonate.\u003c/li\u003e\n\u003cli\u003eAppend any signature segment. The segment must be present, because \u003ccode\u003eJOSE.JWT.verify/2\u003c/code\u003e needs three segments to parse the token. The signature does not need to verify against the Cloudflare keys.\u003c/li\u003e\n\u003cli\u003eSend a request to the application with the forged JWT in the \u003ccode\u003ecf-access-jwt-assertion\u003c/code\u003e header.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eNimbleZTA.Cloudflare.authenticate/3\u003c/code\u003e returns the claims of the forged token as the authenticated identity, with the \u003ccode\u003estrategy\u003c/code\u003e field set to \u003ccode\u003eservice_token\u003c/code\u003e.\u003c/li\u003e\n\u003c/ol\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "1. Build a JWT payload that carries the `aud`, `common_name`, `exp`, `iat`, `iss`, `sub` and `type` claims. Use the `iss` the application expects, set `exp` to a future timestamp, and set `common_name` to the service token to impersonate.\n2. Append any signature segment. The segment must be present, because `JOSE.JWT.verify/2` needs three segments to parse the token. The signature does not need to verify against the Cloudflare keys.\n3. Send a request to the application with the forged JWT in the `cf-access-jwt-assertion` header.\n4. `NimbleZTA.Cloudflare.authenticate/3` returns the claims of the forged token as the authenticated identity, with the `strategy` field set to `service_token`."
}
],
"value": "* Build a JWT payload that carries the aud, common_name, exp, iat, iss, sub and type claims. Use the iss the application expects, set exp to a future timestamp, and set common_name to the service token to impersonate.\n* Append any signature segment. The segment must be present, because JOSE.JWT.verify/2 needs three segments to parse the token. The signature does not need to verify against the Cloudflare keys.\n* Send a request to the application with the forged JWT in the cf-access-jwt-assertion header.\n* NimbleZTA.Cloudflare.authenticate/3 returns the claims of the forged token as the authenticated identity, with the strategy field set to service_token."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-91187",
"datePublished": "2026-09-24T13:20:52.974Z",
"dateReserved": "2026-09-15T15:30:01.892Z",
"dateUpdated": "2026-09-24T14:47:30.520Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89169 (GCVE-0-2026-89169)
Vulnerability from cvelistv5 – Published: 2026-09-11 04:44 – Updated: 2026-09-11 15:57- CWE-347 - Improper Verification of Cryptographic Signature
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89169",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T15:56:11.142588Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T15:57:27.751Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "live-boot",
"vendor": "Debian",
"versions": [
{
"status": "affected",
"version": "ff8867c4e2d62e497cb895b15b7d6d518d5adff1",
"versionType": "git"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "PHYSICAL",
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T05:19:34.404Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146422"
},
{
"url": "https://salsa.debian.org/live-team/live-boot/-/blob/ff8867c4e2d62e497cb895b15b7d6d518d5adff1/components/9990-overlay.sh#L112-114"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-89169",
"datePublished": "2026-09-11T04:44:26.338Z",
"dateReserved": "2026-09-11T04:44:26.012Z",
"dateUpdated": "2026-09-11T15:57:27.751Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89086 (GCVE-0-2026-89086)
Vulnerability from cvelistv5 – Published: 2026-09-10 19:52 – Updated: 2026-09-10 21:00- CWE-347 - Improper Verification of Cryptographic Signature
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89086",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T20:40:09.935199Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T21:00:25.030Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:opam/jose",
"product": "jose",
"vendor": "OCaml",
"versions": [
{
"lessThan": "0.11.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T19:52:47.039Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://github.com/ulrikstrid/ocaml-jose/commit/cf17d991ec6a0d1997956b6c7799890f9c28879e"
},
{
"url": "https://osv.dev/vulnerability/OSEC-2026-19"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-89086",
"datePublished": "2026-09-10T19:52:47.039Z",
"dateReserved": "2026-09-10T19:52:46.560Z",
"dateUpdated": "2026-09-10T21:00:25.030Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89043 (GCVE-0-2026-89043)
Vulnerability from cvelistv5 – Published: 2026-09-10 17:39 – Updated: 2026-09-10 17:53- CWE-347 - Improper Verification of Cryptographic Signature
| URL | Tags |
|---|---|
| https://github.com/krakenjs/passport-saml-encrypt… | issue-tracking |
| https://github.com/krakenjs/passport-saml-encrypt… | technical-description |
| https://github.com/krakenjs/passport-saml-encrypt… | technical-description |
| https://github.com/krakenjs/passport-saml-encrypted | product |
| https://www.vulncheck.com/advisories/passport-sam… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| krakenjs | passport-saml-encrypted |
Affected:
0 , ≤ 0.1.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89043",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T17:53:33.236465Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T17:53:56.984Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/issues/30"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://www.npmjs.com/package/passport-saml-encrypted",
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/passport-saml-encrypted",
"product": "passport-saml-encrypted",
"repo": "https://github.com/krakenjs/passport-saml-encrypted",
"vendor": "krakenjs",
"versions": [
{
"lessThanOrEqual": "0.1.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yu Bao, PayPal Cyber Security Team"
}
],
"datePublic": "2026-08-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the verified identity while the genuine signature validates against the original assertion."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T17:39:33.458Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Reporter advisory: XML signature wrapping",
"tags": [
"issue-tracking"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/issues/30"
},
{
"name": "Signature located by an unconstrained XPath at v0.1.13",
"tags": [
"technical-description"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L256"
},
{
"name": "Assertion selected by a separate first-match XPath at v0.1.13",
"tags": [
"technical-description"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L328"
},
{
"name": "krakenjs/passport-saml-encrypted",
"tags": [
"product"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted"
},
{
"name": "VulnCheck Advisory: passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-xml-signature-wrapping-via-assertion-prepending"
}
],
"title": "passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-89043",
"datePublished": "2026-09-10T17:39:33.458Z",
"dateReserved": "2026-09-10T16:45:09.299Z",
"dateUpdated": "2026-09-10T17:53:56.984Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89042 (GCVE-0-2026-89042)
Vulnerability from cvelistv5 – Published: 2026-09-10 17:39 – Updated: 2026-09-11 20:32- CWE-347 - Improper Verification of Cryptographic Signature
| URL | Tags |
|---|---|
| https://github.com/krakenjs/passport-saml-encrypt… | issue-tracking |
| https://github.com/krakenjs/passport-saml-encrypt… | technical-description |
| https://github.com/krakenjs/passport-saml-encrypt… | technical-description |
| https://github.com/krakenjs/passport-saml-encrypted | product |
| https://www.vulncheck.com/advisories/passport-sam… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| krakenjs | passport-saml-encrypted |
Affected:
0 , ≤ 0.1.13
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89042",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T17:09:27.774740Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T20:32:56.136Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://www.npmjs.com/package/passport-saml-encrypted",
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/passport-saml-encrypted",
"product": "passport-saml-encrypted",
"repo": "https://github.com/krakenjs/passport-saml-encrypted",
"vendor": "krakenjs",
"versions": [
{
"lessThanOrEqual": "0.1.13",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yu Bao, PayPal Cyber Security Team"
}
],
"datePublic": "2026-08-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T17:39:32.769Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Reporter advisory: authentication bypass when cert is not configured",
"tags": [
"issue-tracking"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/issues/29"
},
{
"name": "Signature check gated on options.cert at v0.1.13",
"tags": [
"technical-description"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L296"
},
{
"name": "Same gate on the decrypted-assertion path at v0.1.13",
"tags": [
"technical-description"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L321"
},
{
"name": "krakenjs/passport-saml-encrypted",
"tags": [
"product"
],
"url": "https://github.com/krakenjs/passport-saml-encrypted"
},
{
"name": "VulnCheck Advisory: passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-authentication-bypass-via-missing-signature-verification"
}
],
"title": "passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-89042",
"datePublished": "2026-09-10T17:39:32.769Z",
"dateReserved": "2026-09-10T16:45:04.646Z",
"dateUpdated": "2026-09-11T20:32:56.136Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87802 (GCVE-0-2026-87802)
Vulnerability from cvelistv5 – Published: 2026-09-14 10:22 – Updated: 2026-09-14 19:39- CWE-347 - Improper verification of cryptographic signature
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/gx83cootj00kn8hqd… | vendor-advisory |
| http://www.openwall.com/lists/oss-security/2026/0… |
| Vendor | Product | Version | |
|---|---|---|---|
| Apache Software Foundation | Apache Syncope |
Affected:
3.0.0-M0 , ≤ 3.0.16
(semver)
Affected: 4.0.0-M0 , ≤ 4.0.7 (semver) Affected: 4.1.0-M0 , ≤ 4.1.2 (semver) |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-14T18:09:26.256Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/14/25"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-87802",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T19:39:06.982847Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T19:39:26.483Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.syncope:syncope-sra",
"packageURL": "pkg:maven/org.apache.syncope/syncope-sra",
"product": "Apache Syncope",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "3.0.16",
"status": "affected",
"version": "3.0.0-M0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.0.7",
"status": "affected",
"version": "4.0.0-M0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.1.2",
"status": "affected",
"version": "4.1.0-M0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "MopMonk AI"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eImproper verification of cryptographic signature vulnerability in Apache Syncope.\u003c/p\u003e\u003cp\u003eWhen SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.\u003cbr\u003e\u003cbr\u003eThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.\u003c/p\u003e"
}
],
"value": "Improper verification of cryptographic signature vulnerability in Apache Syncope.\n\n\n\nWhen SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\n\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue."
}
],
"metrics": [
{
"other": {
"content": {
"text": "low"
},
"type": "Textual description of severity"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper verification of cryptographic signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T10:22:29.574Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread/gx83cootj00kn8hqd73x1bp8441np33d"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Apache Syncope: SRA OAuth2 JWT signature verification bypass",
"x_generator": {
"engine": "Vulnogram 1.0.3"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-87802",
"datePublished": "2026-09-14T10:22:29.574Z",
"dateReserved": "2026-09-09T10:11:18.664Z",
"dateUpdated": "2026-09-14T19:39:26.483Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87732 (GCVE-0-2026-87732)
Vulnerability from cvelistv5 – Published: 2026-09-09 04:03 – Updated: 2026-09-09 13:11- CWE-347 - Improper Verification of Cryptographic Signature
| Vendor | Product | Version | |
|---|---|---|---|
| OCaml | mirage-crypto |
Affected:
0 , < 2.2.0
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87732",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T13:11:34.596764Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T13:11:54.773Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://osv.dev/vulnerability/OSEC-2026-12"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:opam/mirage-crypto",
"product": "mirage-crypto",
"vendor": "OCaml",
"versions": [
{
"lessThan": "2.2.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 6.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T04:05:10.227Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://osv.dev/vulnerability/OSEC-2026-12"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-87732",
"datePublished": "2026-09-09T04:03:53.056Z",
"dateReserved": "2026-09-09T04:03:52.629Z",
"dateUpdated": "2026-09-09T13:11:54.773Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-87004 (GCVE-0-2026-87004)
Vulnerability from cvelistv5 – Published: 2026-09-30 17:01 – Updated: 2026-09-30 18:01- CWE-347 - Improper Verification of Cryptographic Signature
| URL | Tags |
|---|---|
| https://github.com/Quenary/tugtainer/security/adv… | x_refsource_CONFIRM |
| https://github.com/Quenary/tugtainer/commit/b5526… | x_refsource_MISC |
| https://github.com/Quenary/tugtainer/releases/tag… | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-87004",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T18:00:13.050961Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T18:01:20.063Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "tugtainer",
"vendor": "Quenary",
"versions": [
{
"status": "affected",
"version": "\u003c 1.31.3"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider\u0027s token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347: Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T17:01:24.963Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh"
},
{
"name": "https://github.com/Quenary/tugtainer/commit/b55269b6a3bfd43b0f2f5bd5f137ee0c81b7c2e4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Quenary/tugtainer/commit/b55269b6a3bfd43b0f2f5bd5f137ee0c81b7c2e4"
},
{
"name": "https://github.com/Quenary/tugtainer/releases/tag/v1.31.3",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Quenary/tugtainer/releases/tag/v1.31.3"
}
],
"source": {
"advisory": "GHSA-crjc-6vc7-xrfh",
"discovery": "UNKNOWN"
},
"title": "Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-87004",
"datePublished": "2026-09-30T17:01:24.963Z",
"dateReserved": "2026-09-08T16:44:23.782Z",
"dateUpdated": "2026-09-30T18:01:20.063Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86585 (GCVE-0-2026-86585)
Vulnerability from cvelistv5 – Published: 2026-09-16 10:13 – Updated: 2026-09-16 17:47- CWE-347 - Improper Verification of Cryptographic Signature
| URL | Tags |
|---|---|
| https://fermax.com/security-advisories | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Fermax Electronica S.A.U. | DUOX PLUS monitor firmware (VEO Wi-Fi range) |
Affected:
0 , < 01.48.001
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86585",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T17:46:48.324132Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T17:47:00.863Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"VEO-WIFI",
"VEO-XS-WIFI",
"VEO-XS-WIFI-DDA",
"VEO-XL-WIFI",
"VEO-XL-WIFI-DDA"
],
"product": "DUOX PLUS monitor firmware (VEO Wi-Fi range)",
"vendor": "Fermax Electronica S.A.U.",
"versions": [
{
"lessThan": "01.48.001",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Pedro J. N\u00fa\u00f1ez-Cacho Fuentes (Tunelko)"
},
{
"lang": "en",
"type": "coordinator",
"value": "INCIBE-CERT"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.\u003c/p\u003e"
}
],
"value": "The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "CWE-347 Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T10:13:22.416Z",
"orgId": "539080bd-5750-4cce-b30b-eed9a4ef6dcc",
"shortName": "FERMAX"
},
"references": [
{
"name": "Fermax security advisories",
"tags": [
"vendor-advisory"
],
"url": "https://fermax.com/security-advisories"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Improper Verification of the Firmware Signature vulnerability",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "539080bd-5750-4cce-b30b-eed9a4ef6dcc",
"assignerShortName": "FERMAX",
"cveId": "CVE-2026-86585",
"datePublished": "2026-09-16T10:13:22.416Z",
"dateReserved": "2026-09-08T07:00:51.689Z",
"dateUpdated": "2026-09-16T17:47:00.863Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
No mitigation information available for this CWE.
CAPEC-463: Padding Oracle Crypto Attack
An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). In addition to performing decryption, an adversary is also able to produce valid ciphertexts (i.e., perform encryption) by using the padding oracle, all without knowing the encryption key.
CAPEC-475: Signature Spoofing by Improper Validation
An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.