CVE-2026-90452 - CERT CVE
ID CVE-2026-90452
Sažetak Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impersonate the identity provider and issue forged authentication tokens accepted by the deployment.
Reference
CVSS
Base: 5.3
Impact: 3.6
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH NONE
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Zadnje važnije ažuriranje 02-10-2026 - 21:16
Objavljeno 11-09-2026 - 22:16