Unknown · Nimble Zta · CVE-2026-91187
**Name of the Vulnerable Software and Affected Versions**
nimble zta versions 0.1.2 through 0.1.2
**Description**
Improper verification of cryptographic signatures in the Cloudflare Zero Trust authentication strategy allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. The `verify token/2` function in `lib/nimble zta/cloudflare.ex` incorrectly handles the result of `JOSE.JWT.verify/2` by discarding the boolean verification result and returning the decoded token even after a failed signature check. An attacker can exploit this by sending a forged JSON Web Token (JWT) in the `cf-access-jwt-assertion` header containing the expected `iss` claim and seven service token claims. Because `verify iss/2` reads the `iss` claim from the forged token without validation, the system accepts the forged claims as a legitimate authenticated identity.
**Recommendations**
Update nimble zta to version 0.1.3.
As a temporary workaround, disable the Cloudflare authentication strategy.
Alternatively, manually reject requests if the JWT in the `cf-access-jwt-assertion` header contains both the `common name` and `type` claims before calling the `NimbleZTA.Cloudflare.authenticate/3` function.