PT-2026-2356 · Cobbr+1 · Covenant
Coastal
·
Published
2026-01-13
·
Updated
2026-01-29
·
CVE-2020-36911
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Covenant versions 0.1.3 through 0.5
Description
The software contains a remote code execution issue that allows attackers to create malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system. The vulnerability involves crafting JWT tokens to gain unauthorized access and execute code.
Recommendations
Update to a newer version that addresses this issue.
Exploit
Fix
RCE
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Covenant