SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88819

MEDIUM · CVSS 6.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in Siglet's refresh token handler allows unauthorized access due to the lack of proof of possession enforcement for the issuer's Decentralized Identifier (DID). This could potentially lead to unauthorized token refreshes and access to sensitive user data. Organizations utilizing Siglet should prioritize addressing this issue to mitigate risks associated with token misuse.

CVE
CVE-2026-88819
Severity
MEDIUM
CVSS
6.3
EPSS
N/A

Original NVD Description

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.