ZeroHour

CVE-2026-88819

CVSS 4.0
6.3 medium
EPSS
Published
()
Modified
Description

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

Weakness
CWE-290, CWE-345
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.