🚨 CVE-2026-75759

CVENOTIFYneutral2026-08-30 02:40:52 UTC
AdYour ad here[email protected]

🚨 CVE-2026-75759 Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. oidcc instead accepted a JWE wrapping…

Read the full story at cvenotify ↗
AdYour ad here[email protected]