THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75759 — Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted

[NVD] CVE-2026-75759 — Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted

mednvdPublished 2026-08-30

CVE-2026-75759 CVSS: None Published: 2026-08-30T02:18:30.110

Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted ID token be signed then encrypted, with the result being

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75759