Unauthenticated session revocation via unverified token claims
Published Aug 1, 2026 · Updated Aug 1, 2026
Cryptographic signature verification failure in Guardian 1.0.0 through 2.4.0 allows remote attackers to revoke victim sessions. Guardian.revoke/3 passes claims decoded by the non-verifying peek/1 function to state-mutating revoke and on_revoke callbacks. No authentication is required, but exploitation requires known or guessed jti or sub claims, a caller-supplied token path, and a state-mutating token module; the default no-op callback is not exploitable.
Summary
What happened
Cryptographic signature verification failure in Guardian 1.0.0 through 2.4.0 allows remote attackers to revoke victim sessions. Guardian.revoke/3 passes claims decoded by the non-verifying peek/1 function to state-mutating revoke and on_revoke callbacks. No authentication is required, but exploitation requires known or guessed jti or sub claims, a caller-supplied token path, and a state-mutating token module; the default no-op callback is not exploitable.
The record
- CVE
- CVE-2026-55735
- Published
- Aug 1, 2026
- Updated
- Aug 1, 2026
- Vendor
- ueberauth
- Product
- Guardian
- Classifications
- CWE-347, CAPEC-475, T1531
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 1, 2026CVE publishedPublication date reported by the CVE source.
- Aug 1, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1.0.0 <2.4.1
- Affected versionversion=d65227145f72b290106c06cecbe42728fbf05fe2 <2bd7a8c29770d423d855c0a4965caa6c3e486901
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Forged-token session revocation proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo