CVE-2026-64623 Details
Description
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.
A vulnerability exists in the APSAdapter component of Network-AI versions prior to 5.13.4, where the default local signature verifier improperly accepts any non-empty string as a valid signature. This flaw allows unauthenticated attackers to submit forged APS delegation payloads with arbitrary scopes, bypassing signature verification. Exploitation of this vulnerability enables the attacker to obtain signed permission-grant tokens for sensitive resources, including SHELL_EXEC, thereby escalating privileges without authentication at the adapter layer.
Users can update to Network-AI version 5.13.4 or later, where this vulnerability has been patched. Additionally, when using APSAdapter, it's recommended to provide a custom verifySignature callback that implements proper cryptographic signature verification.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-3jf7-33vc-hgf4 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Jovancoding/Network-AI/security/advisories/GHSA-3jf7-33vc-hgf4 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/network-ai-before-cryptographic-signature-verification-bypass | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Jovancoding Network-AI | <= 5.13.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion