CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass
Low-severity CVE-2026-87802 in Apache Syncope SRA allows JWT signature forgery in OAuth 2.0 setups without JWKS URI.
CVE-2026-87802 is a low-severity improper cryptographic signature verification flaw in Apache Syncope SRA affecting versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. When SRA is configured for OAuth 2.0 without a JWKS set URI assigned, an attacker can forge tokens, bypassing JWT signature verification.
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust bug letting untrusted repositories execute commands, then closed the report as informative.
A security flaw in the Cursor editor allowed repositories to execute commands before the user completed workspace trust verification. Cursor fixed the pre-trust code execution path within three days of receiving the report. The vendor then closed the report as informative, disputing the severity of the behavior.