CVE-2026-36721
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
Published 2026-06-09. Last modified 2026-07-23.