CVE-2026-64623: Jovancoding Network-Ai
High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers can submit forged APS delegation payloads with arbitrary scopes to bypass signature verification and obtain signed permission-grant tokens for sensitive resources including SHELL_EXEC.
Affected products
- Jovancoding Network-Ai: before 5.13.4 (fixed in 5.13.4)
Published 2026-07-20. Last modified 2026-07-23.