SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-53939

CRITICAL · CVSS 9.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the OpenIDC/cjose library in versions 0.6.1 to 0.6.2.5, where the content-encryption key (CEK) for JWE encrypted using AES-CBC-HMAC algorithms is incorrectly generated as all zero bytes, allowing attackers to decrypt and modify the content. This critical flaw poses a significant risk to any application relying on this library for secure data transmission, particularly those handling sensitive information. Organizations using affected versions should prioritize immediate upgrades to version 0.6.2.6 or implement alternative encryption strategies to mitigate the risk of data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53939
Severity
CRITICAL
CVSS
9.1
EPSS
0.20%
Java

Original NVD Description

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).