← Back to the live CVE advisory feed

CVE-2026-75759: oidcc

Severity
7.6 (HIGH)
Vendor
ERLEF
Affected versions
3.2.0-beta.1 through before 3.9.0; 37a1361f704889816db2873f72d744d63ec39568 through before 5f62fbccdae8526ff62653b890165
Fixed version
3.9.0.
Patch status
Patched
Published
2026-08-30T02:18:30.110
Modified
2026-08-30T02:18:30.110

Why it matters

This matters because the issue affects identity or token handling. Successful exploitation could allow unauthorized authentication, client manipulation, or access to protected services.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being a Nested JWT, and JARM processing rule 5 requires the client to check the signature unconditionally. oidcc instead accepted a JWE wrapping unsigned claims as fully validated, so anyone holding the relying party's public encryption key could mint a token with an arbitrary sub, iss, and aud without possessing the provider's signing key. In oidcc_jwt_util:verify_decrypted_token/4, a decrypted payload that is not a signed JWS fell back to parsing the plaintext claims and returning them with no verifying key. oidcc_token:int_validate_jwt/4 then matched on the JOSE structure type rather than on whether a signature had been verified, and returned success. The JARM path in oidcc_token:validate_jarm/3 is reachable through the browser front channel. UserInfo responses are not affected, because OpenID Connect Core 1.0 section 5.3.2 permits them to be encrypted without also being signed. This issue affects oidcc: from 3.2.0-beta.1 before 3.9.0.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: AUG 30, 2026 08:00 AM UTC
56 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-82456
argocd-mcp
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-14494
SigmaForms Pro – AI Generated Forms
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-15369
Custom User Registration Fields for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-15980
MyHome Core
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-82466
rodauth PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-82448
Shinobi
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-82452
rust-iot-platform
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-82454
omnivore
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-82460
cloudcmd PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-82473
kubeedge
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-82447
skyvern PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-82450
bookstack PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-82453
rust-iot-platform
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-82481
cohttp PATCH
Reporter: CVE
8.7
HIGH
VIEW RECORD
CVE-2026-82472
documenso PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-82461
pac4j PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-82463
pac4j PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-82475
astron-agent
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-82457
su-exec
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-82474
sudo
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-75759
oidcc PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
7.6
HIGH
VIEW RECORD
CVE-2026-75807
SAML Single Sign On – SSO Login
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-82449
cockpit PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-82455
rubygems
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-82462
pac4j PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-82465
pac4j PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-82476
memos
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-82478
Trick
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-82417
qs PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
6.3
MEDIUM
VIEW RECORD
CVE-2026-82562
qs PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
6.3
MEDIUM
VIEW RECORD
CVE-2026-75847
ash_paper_trail PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
5.9
MEDIUM
VIEW RECORD
CVE-2026-77970
ash_paper_trail PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
5.9
MEDIUM
VIEW RECORD
CVE-2026-82477
Heimdall PATCH
Reporter: CVE
5.8
MEDIUM
VIEW RECORD
CVE-2026-82451
Formwork
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-82464
pac4j PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-82479
cFS
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-82480
cFS
Reporter: CNA
5.3
MEDIUM
VIEW RECORD
CVE-2026-82469
rodauth PATCH
Reporter: DISCLOSURE
5.1
MEDIUM
VIEW RECORD
CVE-2026-82470
rodauth PATCH
Reporter: DISCLOSURE
5.1
MEDIUM
VIEW RECORD
CVE-2026-82467
rodauth PATCH
Reporter: DISCLOSURE
4.9
MEDIUM
VIEW RECORD
CVE-2026-82468
rodauth PATCH
Reporter: DISCLOSURE
4.9
MEDIUM
VIEW RECORD
CVE-2026-82364
mall
Reporter: CNA
2.3
LOW
VIEW RECORD
CVE-2026-82421
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-82422
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-82423
mall
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-82424
Student Information System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-77831
ash_paper_trail PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
2.1
LOW
VIEW RECORD
CVE-2026-77846
ash_sqlite PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
2.1
LOW
VIEW RECORD
CVE-2026-82482
Coppermine Photo Gallery PATCH
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-14307
geotargetingwp PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-14835
SOGO Add Script to Individual Pages Header Footer
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-19722
WPvivid — Backup, Migration & Staging PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-76585
Customer Reviews for WooCommerce PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-78364
MW WP Form PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-81660
Groundhogg — CRM, Newsletters, and Marketing Automation PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD
CVE-2026-81766
Really Simple Security PATCH
Reporter: CONTACT
0
N/A
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.