Improper Verification in nimble_zta by Dashbit Allows Unauthorized Authentication
CVE-2026-91187
9.3CRITICAL
What is CVE-2026-91187?
An improper verification vulnerability in Dashbit's nimble_zta allows unauthenticated remote attackers to authenticate as any Cloudflare service token. This arises from the flawed handling of JSON Web Tokens (JWTs), where the expectation of signature verification is not properly enforced. Attackers can craft a forged JWT with the necessary claims, bypassing authentication mechanisms and impersonating valid service tokens, thereby compromising the integrity of applications leveraging Cloudflare's Zero Trust authentication.
Affected Version(s)
nimble_zta 0.1.2 < 0.1.3
nimble_zta bc004b70985ae5763901baab3a4e204047899768 < 6458fd18a5ba41166d4973214c519e98fe05b72d
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kazlu
José Valim / Dashbit
Jonatan Männchen / EEF
