PT-2026-21965 · Opensips · Opensis

·

CVE-2026-25554

·

Published

2026-02-25

·

Updated

2026-03-19

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenSIPS versions 3.1 through 3.6.3
Description The software contains a SQL injection issue within the jwt db authorize() function in the auth jwt module when a SQL database backend is used and db mode is enabled. The function incorporates a tag claim from a JWT directly into a SQL query without verifying the signature first. An attacker can craft a malicious JWT with a specially designed tag claim to manipulate the query and bypass authentication, potentially impersonating other users.
Recommendations Update to version 3.6.4 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25554

Affected Products

Opensis