CVE-2026-87004 | Quenary Tugtainer up to 1.31.2 OIDC Provider auth_oidc_provider.py jose.jwt.get_unverified_claims signature verification

SecurityVulns

A vulnerability classified as critical was found in Quenary Tugtainer up to 1.31.2. Affected by this issue is the function jose.jwt.get_unverified_claims of the file backend/modules/auth/providers/auth_oidc_provider.py of the component OIDC Provider. The manipulation results in improper verification of cryptographic signature.

This vulnerability is cataloged as CVE-2026-87004. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More