Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91187— Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy

Quick assessment

Affected
dashbit nimble_zta
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

nimble_zta 中的加密签名验证不当漏洞,允许未经身份验证的远程攻击者以任意 Cloudflare 服务令牌的身份进行认证。使用 Cloudflare 零信任(Zero Trust)认证策略的应用程序均受影响。 在 文件中的 函数中,代码使用 模式匹配 的返回结果。这种写法丢弃了布尔型验证结果,并在签名验证失败的情况下仍返回已解码的令牌。攻击者可在 头中伪造一个 JWT,其中包含预期的 (签发者)声明以及七个服务令牌声明。 函数从伪造的令牌中读取 声明,因此不会拒绝该令牌;随后服务令牌路径会将这些声明作为已认

CVSS 9.3 · Critical EPSS 0.30% · P21
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91187

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected. verify_token/2 in lib/nimble_zta/cloudflare.ex matches the result of JOSE.JWT.verify/2 against {_, token, _s}, which discards the boolean verification result and returns the decoded token after a failed signature check. The attacker sends a forged JWT in the cf-access-jwt-assertion header, carrying the expected iss claim and the seven service token claims. verify_iss/2 reads the iss claim from the forged token, so it rejects nothing, and the service token path then returns those claims as the authenticated identity. This issue affects nimble_zta: from 0.1.2 before 0.1.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
dashbit nimble_zta 0.1.2 ~ 0.1.3 cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:*
dashbit nimble_zta bc004b70985ae5763901baab3a4e204047899768 ~ 6458fd18a5ba41166d4973214c519e98fe05b72d cpe:2.3:a:dashbit:nimble_zta:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-91187

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91187

请登录查看更多情报信息。

Other References for CVE-2026-91187 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91187

No comments yet


Leave a comment