Review reviewCritical
CVE-2026-36721
the affected product
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
- CVSS
- 9.8
- EPSS
- 0.27% 18.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10