CVE Explorer
CVE-2026-33746
Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated time-based claims (exp, nbf, iat) using the StrictValidAt constraint. The SignedWith constraint was not included in the validation step. This means an attacker could forge or tamper with JWT token paylo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"panel","vendor":"ConvoyPanel","versions":[{"status":"affected","version":">= 3.9.0-beta, < 4.5.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"name":"https://github.com/ConvoyPanel/panel/releases/tag/v4.5.1","tags":["x_refsource_MISC"],"url":"https://github.com/ConvoyPanel/panel/releases/tag/v4.5.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/references/1
{"name":"https://github.com/ConvoyPanel/panel/security/advisories/GHSA-92pg-3w49-4w5x","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ConvoyPanel/panel/security/advisories/GHSA-92pg-3w49-4w5x"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d742e568b926f6ee1ebdb64122a2455928318f1e9cdebab3cda87827cdbe9b8e · sha256:e5435038647bf2da… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.