logo

Critical JWT Bypass in Convoy Panel Allows Full Account Takeover

ID: 875e6c27-0c92-5d08-a1f6-1443ca24eddf

STIX ID: report--875e6c27-0c92-5d08-a1f6-1443ca24eddf

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVE-2026-33746 vulnerability in Convoy’s JWT-based SSO (CVSS 9.8) omitted signature verification in JWTService::decode(), allowing attackers to forge tokens and authenticate as any user, including administrators. The flaw affects Convoy versions prior to 4.5.1, has no practical workaround, and is fixed by upgrading to v4.5.1 which adds the SignedWith constraint to validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.