CVE-2026-36721

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

Published 2026-06-09. Last modified 2026-07-23.