Authentication Bypass in Omnivore API Affects Apple Sign-In Functionality
CVE-2026-82454
9.3CRITICAL
What is CVE-2026-82454?
The Omnivore API contains a vulnerability that allows attackers to bypass authentication through Apple's sign-in mechanism. This flaw arises from improper handling of the JWT header, specifically the 'alg' field in the decodeAppleToken function. By supplying a malicious token and using the HS256 algorithm, an attacker can create a forged token leveraging Apple's RSA public key as a HMAC secret. This enables unauthorized access, allowing attackers to impersonate legitimate Apple-linked accounts without validating the authenticity of the token.
Affected Version(s)
omnivore 0
