SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72889

CRITICAL · CVSS 9.8 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Net::OAuth versions prior to 0.33 for Perl are vulnerable as they allow the sender to dictate the signature algorithm used in the verification process, potentially leading to signature forgery. This flaw enables an attacker to exploit the system by crafting requests with guessable signatures, undermining the integrity of the authentication mechanism. Organizations utilizing affected versions of Net::OAuth should prioritize remediation to safeguard against unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72889
Severity
CRITICAL
CVSS
9.8
EPSS
0.35%

Original NVD Description

Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to check a signature is chosen by whoever sent it, and nothing lets the verifying party pin the method instead. When a message names HMAC-SHA1 or HMAC-SHA256, the key is derived from consumer_secret and token_secret rather than from the key the provider deployed. A provider deployed on RSA-SHA1 holds only the consumer public key, and RFC 5849 does not use consumer_secret for that method, so the required parameter is filled with a placeholder. A client that names HMAC-SHA1 instead has its signature checked against that placeholder, so a guessable one is enough to forge requests for any consumer key and token.