Authentication Bypass in Malach-IT Boruta OAuth Client
CVE-2026-53431

9.1CRITICAL

Key Information:

Vendor

Malach-it

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-53431?

An Authentication Bypass by Capture-replay vulnerability exists in the Malach-IT Boruta, allowing attackers to exploit valid JWT client assertions. Boruta does not adequately check the expiration of these assertions, permitting indefinite replay of tokens and unauthorized access to client privileges. Attackers can leverage previously valid assertions obtained through various means, including logs or browser tools, thus undermining the security intended by the OAuth protocol. This flaw is present in Boruta versions up to 2.3.6.

Affected Version(s)

boruta 2.3.0 < 2.3.7

boruta 5bfbe1c5443bffe71cf1bf954bbdff61327d9a83

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pascal Knoth
Pascal Knoth
Jonatan Männchen / EEF
.