Authentication Bypass in Malach-IT Boruta OAuth Client
CVE-2026-53431
9.1CRITICAL
What is CVE-2026-53431?
An Authentication Bypass by Capture-replay vulnerability exists in the Malach-IT Boruta, allowing attackers to exploit valid JWT client assertions. Boruta does not adequately check the expiration of these assertions, permitting indefinite replay of tokens and unauthorized access to client privileges. Attackers can leverage previously valid assertions obtained through various means, including logs or browser tools, thus undermining the security intended by the OAuth protocol. This flaw is present in Boruta versions up to 2.3.6.
Affected Version(s)
boruta 2.3.0 < 2.3.7
boruta 5bfbe1c5443bffe71cf1bf954bbdff61327d9a83
References
CVSS V4
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pascal Knoth
Pascal Knoth
Jonatan Männchen / EEF
