CVE-2026-27962
Authlib accepts a key embedded in the token
Before Authlib 1.6.9, JWS verification can use a key carried in the token when the caller passes no key. NVD scores it 9.1. It is not the later empty-signatures bug.
- CVSS
- 9.1
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Authlib
- Products
- Authlib
- Affected
- Versions before 1.6.9. The GitHub advisory range is 1.6.8 and earlier. The bypass applies when verification is called with no key.
- Fixed
- 1.6.9
- CWE
- CWE-347
- Published
- 16 Mar 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-27962 is a JWS verification bypass in Authlib before 1.6.9. GitHub advisory GHSA-wvwj-cvrp-7pv5, published 16 March 2026, says that when the caller passes no key, the library can take a key from the token header and treat that signature as valid. NVD scores it 9.1, with high confidentiality and integrity impact and no availability impact. The weakness is CWE-347.
The advisory’s vulnerable range is 1.6.8 and earlier. The release that NVD names as the patch is 1.6.9. CISA has not listed the CVE, and this record has no confirmed public proof-of-concept repository. It is a different bug from CVE-2026-28802 and from CVE-2026-96760.