CyberRota Analysis
AI-GeneratedThe vulnerability in Siglet's refresh token handler allows unauthorized access due to the lack of proof of possession enforcement for the issuer's Decentralized Identifier (DID). This could potentially lead to unauthorized token refreshes and access to sensitive user data. Organizations utilizing Siglet should prioritize addressing this issue to mitigate risks associated with token misuse.
CVE
CVE-2026-88819
Severity
MEDIUM
CVSS
6.3
EPSS
N/A
Original NVD Description
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.