Security Advisory

CVE-2026-36727

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-09 00:00:00
Last updated 2026-06-10 18:50:12
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.