Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j4h7-9cc4-7f3r

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

EPSS

Процентиль: 42%
0.00498
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 10
nvd
2 месяца назад

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated remote attacker to forge arbitrary JWT, bypass authentication mechanisms and impersonate any user including administrative accounts, potentially gaining full unauthorized access to the application.

CVSS3: 10
fstec
2 месяца назад

Уязвимость облачного программного обеспечения для цифрового производства Opcenter X, связанная с ошибками проверки криптографической подписи, позволяющая нарушителю получить полный доступ к приложению

EPSS

Процентиль: 42%
0.00498
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-347