The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 09:17
Updated : 2026-08-26 17:13
NVD link : CVE-2026-77130
Mitre link : CVE-2026-77130
CVE.ORG link : CVE-2026-77130
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
