Critical severity9.8NVD Advisory· Published May 2, 2023· Updated Jun 17, 2026
CVE-2023-26089
CVE-2023-26089
Description
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
Affected products
2- European Chemicals Agency/IUCLIDdescription
- Range: 5.15.0 through 6.27.5
Patches
Vulnerability mechanics
References
3- iuclid6.echa.europa.eu/documents/1387205/1809530/note_v6.27.6.pdf/76545a65-e6be-6486-280a-7d7c3d2ad455nvdMitigationVendor Advisory
- iuclid6.echa.europa.eunvdProduct
- iuclid6.echa.europa.eu/downloadnvdProduct
News mentions
0No linked articles in our index yet.