CVSS v3
9.8
CRITICAL
EPSS Score
12.1 %
exploit probability, as of 2026-09-25
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
Technical details
- Published
- 2026-01-13
- Last Modified
- 2026-01-28
Frequently asked questions
What is CVE-2020-36911?
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
Is CVE-2020-36911 actively exploited?
Active exploitation of CVE-2020-36911 has not been confirmed. Its EPSS score was 12.1% on 2026-09-25, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2020-36911?
CVE-2020-36911 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2020-36911 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2020 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).