← לוח פגיעויות

CVE-2026-88819

בינונית 6.3

תיאור (מקור, אנגלית)

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

מדדים

CVSS 4.0
6.3 (MEDIUM) מקור הציון: CNA CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-1/10/2026
CWE
CWE-290, CWE-345

קישורים