Review reviewCritical
CVE-2026-36727
the affected product
An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
- CVSS
- 9.1
- EPSS
- 0.36% 29.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.10