Network-AI before 5.13.4 Cryptographic Signature Verification Bypass
CVSS v3
8.6
HIGH
EPSS Score
—
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.
A proof-of-concept exploit exists for CVE-2026-64623, but active exploitation has not been confirmed at this time.
CVE-2026-64623 has a CVSS v3 base score of 8.6 (HIGH severity), with vector string 3.1.
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.