Tugtainer · Tugtainer · CVE-2026-87004
**Name of the Vulnerable Software and Affected Versions**
Tugtainer versions prior to 1.31.3
**Description**
During the OIDC login flow, the file `backend/modules/auth/providers/auth oidc provider.py` decodes the `id token` returned by the identity provider using `jose.jwt.get unverified claims()` instead of `jwt.decode()`. This process bypasses signature verification, audience (`aud`) validation, issuer (`iss`) validation, and expiry (`exp`) checking. Consequently, the extracted claims such as `email`, `sub`, or `preferred username` are used directly as the `user id` for the session.
**Recommendations**
Update to version 1.31.3.