HIGH

CVE-2026-64623

Network-AI before 5.13.4 Cryptographic Signature Verification Bypass

CVSS v3

8.6

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.

Technical details

CVSS v3 Vector
3.1
Published
7/20/2026
Last Modified
7/20/2026

Frequently asked questions

What is CVE-2026-64623?

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.

Is CVE-2026-64623 actively exploited?

A proof-of-concept exploit exists for CVE-2026-64623, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-64623?

CVE-2026-64623 has a CVSS v3 base score of 8.6 (HIGH severity), with vector string 3.1.

Is CVE-2026-64623 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.