SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64623

HIGH · CVSS 8.6 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Network-AI versions prior to 5.13.4 are vulnerable due to an improper cryptographic signature verification in the APSAdapter, allowing unauthenticated attackers to exploit this flaw. By submitting forged APS delegation payloads, attackers can bypass signature verification and gain unauthorized access to sensitive resources, including the ability to execute shell commands. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64623
Severity
HIGH
CVSS
8.6
EPSS
0.20%

Original NVD Description

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.