Improper Verification in nimble_zta by Dashbit Allows Unauthorized Authentication
CVE-2026-91187

9.3CRITICAL

Key Information:

Vendor

Dashbit

Vendor
CVE Published:
24 September 2026

What is CVE-2026-91187?

An improper verification vulnerability in Dashbit's nimble_zta allows unauthenticated remote attackers to authenticate as any Cloudflare service token. This arises from the flawed handling of JSON Web Tokens (JWTs), where the expectation of signature verification is not properly enforced. Attackers can craft a forged JWT with the necessary claims, bypassing authentication mechanisms and impersonating valid service tokens, thereby compromising the integrity of applications leveraging Cloudflare's Zero Trust authentication.

Affected Version(s)

nimble_zta 0.1.2 < 0.1.3

nimble_zta bc004b70985ae5763901baab3a4e204047899768 < 6458fd18a5ba41166d4973214c519e98fe05b72d

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazlu
José Valim / Dashbit
Jonatan Männchen / EEF
.