OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-91187

CRITICAL · CVSS 9.3 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in dashbit nimble_zta allows unauthenticated remote attackers to impersonate any Cloudflare service token by exploiting improper verification of cryptographic signatures. This can lead to unauthorized access to applications utilizing Cloudflare's Zero Trust authentication strategy. Organizations using nimble_zta versions from 0.1.2 to before 0.1.3 should prioritize immediate updates to mitigate this critical security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91187
Severity
CRITICAL
CVSS
9.3
EPSS
0.30%

Original NVD Description

Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected. verify_token/2 in lib/nimble_zta/cloudflare.ex matches the result of JOSE.JWT.verify/2 against {_, token, _s}, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the cf-access-jwt-assertion header, carrying the expected iss claim and the seven service token claims. verify_iss/2 reads the iss claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity. This issue affects nimble_zta: from 0.1.2 before 0.1.3.