PT-2026-97797 · Unknown · Nimble Zta

·

CVE-2026-91187

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions nimble zta versions 0.1.2 through 0.1.2
Description Improper verification of cryptographic signatures in the Cloudflare Zero Trust authentication strategy allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. The verify token/2 function in lib/nimble zta/cloudflare.ex incorrectly handles the result of JOSE.JWT.verify/2 by discarding the boolean verification result and returning the decoded token even after a failed signature check. An attacker can exploit this by sending a forged JSON Web Token (JWT) in the cf-access-jwt-assertion header containing the expected iss claim and seven service token claims. Because verify iss/2 reads the iss claim from the forged token without validation, the system accepts the forged claims as a legitimate authenticated identity.
Recommendations Update nimble zta to version 0.1.3. As a temporary workaround, disable the Cloudflare authentication strategy. Alternatively, manually reject requests if the JWT in the cf-access-jwt-assertion header contains both the common name and type claims before calling the NimbleZTA.Cloudflare.authenticate/3 function.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91187
GHSA-RJ24-G8CC-G7G2

Affected Products

Nimble Zta