Token Safe AI Router Vulnerability in 9Router by Decolua
CVE-2026-56677

8.6HIGH

Key Information:

Vendor

Decolua

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-56677?

The 9Router software, designed for optimized token saving and management, contains a security flaw in its authentication endpoint. Specifically, the POST /api/auth/oidc/test route does not adequately validate the user-provided issuerUrl parameter, allowing attackers to exploit this oversight when dashboard login is disabled. This improper validation opens avenues for unauthenticated attackers to probe internal services, potentially revealing sensitive OIDC discovery details, such as the token endpoint and JWKS URI, thereby facilitating unauthorized access to critical services.

Affected Version(s)

9router <= 0.5.4

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.