Skip to main content
CRITICAL

CVE-2020-36911

CVSS v3

9.8

CRITICAL

EPSS Score

12.1 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Technical details

Published
2026-01-13
Last Modified
2026-01-28

Frequently asked questions

What is CVE-2020-36911?

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Is CVE-2020-36911 actively exploited?

Active exploitation of CVE-2020-36911 has not been confirmed. Its EPSS score was 12.1% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-36911?

CVE-2020-36911 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-36911 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key