CVE-2026-43983
Last modified
CVE-2026-43983 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. This allows (1) the client to refresh the token indefinitely after authorization revocation, (2) the refresh token to continue to work after the account is disabled, and (3) the token to work after the client is removed from the group. This vulnerability is fixed in 2.6.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pocket-Id | Pocket Id | < 2.6.0 |
References
- https://github.com/pocket-id/pocket-id/security/advisories/GHSA-w6p7-2fxx-4f44Exploit, Mitigation, Vendor Advisory
- https://github.com/pocket-id/pocket-id/security/advisories/GHSA-w6p7-2fxx-4f44Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-43983?
How severe is CVE-2026-43983?
How do I fix CVE-2026-43983?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43977wger is a free, open-source workout and fitness manager. In …7.5
- CVE-2026-43978wger is a free, open-source workout and fitness manager. In …8.1
- CVE-2026-43979Local Deep Research is an AI-powered research assistant for …5
- CVE-2026-4398Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-43981Algernon is a small self-contained pure-Go web server. Prior…8.2
- CVE-2026-43982Algernon is a small self-contained pure-Go web server. Prior…8.7
- CVE-2026-43984Tautulli is a Python based monitoring and tracking tool for …8.9
- CVE-2026-43985Tautulli is a Python based monitoring and tracking tool for …8.8
- CVE-2026-43986Tautulli is a Python based monitoring and tracking tool for …9.9
- CVE-2026-43988Vanetza is an open-source implementation of the ETSI C-ITS p…7.5
- CVE-2026-43989JunoClaw is an agentic AI platform built on Juno Network. Pr…8.5
- CVE-2026-4399Prompt injection vulnerability in 1millionbot Millie chatbot…7.5
Are you affected by CVE-2026-43983?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
