What is CVE-2026-59243?
CVE-2026-59243: The FAB auth manager's Azure AD OAuth login had `verify_signature=False` set by default when decoding the ID token. This flaw allows an attacker to bypass authentication and log in as any user, including those with Admin roles, by presenting a forged or unsigned (`alg:none`) token to the OAuth callback. Affected systems should be updated immediately.
Azərbaycanca: CVE-2026-59243: FAB autentifikasiya menecerinin Azure AD OAuth girişində ID token `verify_signature=False` olaraq dekodlanırdı. Bu zəiflik təcavüzkara saxta və ya imzasız (`alg:none`) token təqdim edərək, Admin daxil olmaqla istənilən istifadəçi kimi autentifikasiyadan yan keçməyə imkan verir. Təsirə məruz qalan sistemlərdə dərhal FAB versiyasını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
How can CVE-2026-59243 be exploited?
An attacker can bypass authentication on the Azure AD OAuth login by presenting a forged or unsigned (`alg:none`) ID token, allowing login as any user, including those with Admin roles.
What action should be taken for CVE-2026-59243?
Affected systems should immediately update the FAB authentication manager version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.