<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Jwt — PoC Archive</title><link>https://poc.intelseclab.com/tags/jwt/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/jwt/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-49230. Status: Weaponized. Affects: Apache APISIX — jwe-decrypt auth plugin (apisix/plugins/jwe-decrypt.lua). Tags: apache-apisix, jwe, jwt, integrity-bypass, cwe-354, unauthenticated, api-gateway, lua.</description><category>web</category><category>Critical</category><category>apache-apisix</category><category>jwe</category><category>jwt</category><category>integrity-bypass</category><category>cwe-354</category><category>unauthenticated</category><category>api-gateway</category><category>lua</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8). Status: Weaponized (functional PoC forges valid admin JWTs and confirms bypass against real endpoints). Affects: Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware). Tags: flowise, ai-gateway, llm-orchestration, jwt, hardcoded-secret, authentication-bypass, cwe-321, unauthenticated, remote, privilege-escalation.</description><category>web</category><category>Critical</category><category>flowise</category><category>ai-gateway</category><category>llm-orchestration</category><category>jwt</category><category>hardcoded-secret</category><category>authentication-bypass</category><category>cwe-321</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-62168. Status: PoC. Affects: Squid Proxy. Tags: squid, proxy, information-disclosure, header-reflection, jwt, token-leak, error-page, cwe-209, cwe-550.</description><category>network</category><category>Critical</category><category>squid</category><category>proxy</category><category>information-disclosure</category><category>header-reflection</category><category>jwt</category><category>token-leak</category><category>error-page</category><category>cwe-209</category><category>cwe-550</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48558. Status: PoC. Affects: SimpleHelp remote support / remote monitoring &amp; management (RMM) server, OIDC authentication flow. Tags: simplehelp, oidc, jwt, alg-none, auth-bypass, rmm, remote-support, cisa-kev.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>auth-bypass</category><category>rmm</category><category>remote-support</category><category>cisa-kev</category></item><item><title>sealed-env Unseal Token TOTP/Enterprise Secret Disclosure (CVE-2026-45091)</title><link>https://poc.intelseclab.com/pocs/crypto/2026-07-05_cve-2026-45091-sealed-env-totp-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/crypto/2026-07-05_cve-2026-45091-sealed-env-totp-leak/</guid><description>High severity — crypto · CVE-2026-45091. Status: PoC. Affects: sealed-env (davidalmeidac/sealed-env) — unseal token mechanism. Tags: jwt, sealed-env, totp, secret-disclosure, base64, token-forgery.</description><category>crypto</category><category>High</category><category>jwt</category><category>sealed-env</category><category>totp</category><category>secret-disclosure</category><category>base64</category><category>token-forgery</category></item><item><title>pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29000-pac4j-jwt-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29000-pac4j-jwt-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-29000. Status: Weaponized. Affects: pac4j (JWT authentication module), used in Java web applications. Tags: pac4j, jwt, jwe, auth-bypass, alg-none, jwks, privilege-escalation, java.</description><category>web</category><category>Critical</category><category>pac4j</category><category>jwt</category><category>jwe</category><category>auth-bypass</category><category>alg-none</category><category>jwks</category><category>privilege-escalation</category><category>java</category></item><item><title>Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45156-nextcloud-id4me-jwt-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45156-nextcloud-id4me-jwt-bypass/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-45156. Status: PoC. Affects: Nextcloud user_oidc app — ID4me identity provider integration. Tags: nextcloud, user_oidc, id4me, jwt, alg-none, authentication-bypass, cwe-347.</description><category>web</category><category>High</category><category>nextcloud</category><category>user_oidc</category><category>id4me</category><category>jwt</category><category>alg-none</category><category>authentication-bypass</category><category>cwe-347</category></item><item><title>LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-35030-litellm-oidc-cache-collision-authbypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-35030. Status: Weaponized. Affects: LiteLLM proxy (with enable_jwt_auth: true). Tags: authentication-bypass, litellm, oidc, jwt, cache-collision, ai-gateway, cwe-287.</description><category>web</category><category>Critical</category><category>authentication-bypass</category><category>litellm</category><category>oidc</category><category>jwt</category><category>cache-collision</category><category>ai-gateway</category><category>cwe-287</category></item><item><title>Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30368-lightspeed-classroom-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30368-lightspeed-classroom-auth-bypass/</guid><description>High severity — web · CVE-2026-30368. Status: PoC. Affects: Lightspeed Classroom Management (Chrome extension for school device management). Tags: chrome-extension, wasm, jwt, ably, service-worker, education-technology, device-control, browser.</description><category>web</category><category>High</category><category>chrome-extension</category><category>wasm</category><category>jwt</category><category>ably</category><category>service-worker</category><category>education-technology</category><category>device-control</category><category>browser</category></item><item><title>Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1529-keycloak-org-registration-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1529-keycloak-org-registration-bypass/</guid><description>Critical severity — web · CVE-2026-1529. Status: PoC. Affects: Keycloak (organization/invitation feature). Tags: keycloak, jwt, invitation-token, organization-registration, authentication-bypass, sso, wordpress-adjacent, identity-provider.</description><category>web</category><category>Critical</category><category>keycloak</category><category>jwt</category><category>invitation-token</category><category>organization-registration</category><category>authentication-bypass</category><category>sso</category><category>wordpress-adjacent</category><category>identity-provider</category></item></channel></rss>