Authentication Bypass in Omnivore API Affects Apple Sign-In Functionality
CVE-2026-82454

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82454?

The Omnivore API contains a vulnerability that allows attackers to bypass authentication through Apple's sign-in mechanism. This flaw arises from improper handling of the JWT header, specifically the 'alg' field in the decodeAppleToken function. By supplying a malicious token and using the HS256 algorithm, an attacker can create a forged token leveraging Apple's RSA public key as a HMAC secret. This enables unauthorized access, allowing attackers to impersonate legitimate Apple-linked accounts without validating the authenticity of the token.

Affected Version(s)

omnivore 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Sun
.