Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-27962

Authlib accepts a key embedded in the token

Before Authlib 1.6.9, JWS verification can use a key carried in the token when the caller passes no key. NVD scores it 9.1. It is not the later empty-signatures bug.

CVSS
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Authlib
Products
Authlib
Affected
Versions before 1.6.9. The GitHub advisory range is 1.6.8 and earlier. The bypass applies when verification is called with no key.
Fixed
1.6.9
Published
16 Mar 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-27962 is a JWS verification bypass in Authlib before 1.6.9. GitHub advisory GHSA-wvwj-cvrp-7pv5, published 16 March 2026, says that when the caller passes no key, the library can take a key from the token header and treat that signature as valid. NVD scores it 9.1, with high confidentiality and integrity impact and no availability impact. The weakness is CWE-347.

The advisory’s vulnerable range is 1.6.8 and earlier. The release that NVD names as the patch is 1.6.9. CISA has not listed the CVE, and this record has no confirmed public proof-of-concept repository. It is a different bug from CVE-2026-28802 and from CVE-2026-96760.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-27962