CVE-2026-88819

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 16:17

Updated : 2026-09-14 20:17


NVD link : CVE-2026-88819

Mitre link : CVE-2026-88819

CVE.ORG link : CVE-2026-88819


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing

CWE-345

Insufficient Verification of Data Authenticity