Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4h7-9cc4-7f3r

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

EPSS

Процентиль: 23%
0.00305
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 10
nvd
18 дней назад

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

CVSS3: 10
fstec
19 дней назад

Уязвимость облачного программного обеспечения для цифрового производства Opcenter X, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю получить полный доступ к приложению

EPSS

Процентиль: 23%
0.00305
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347