PT-2026-44079 · Unknown · Himmelblau

Ccadruvi

·

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-45108

CVSS v3.1

8.4

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Himmelblau versions 2.0.0 through 3.1.4 Himmelblau versions prior to 2.3.11
Description An authentication bypass exists in the Device Authorization Grant (DAG) flow, which is a process allowing devices with limited input capabilities to be authenticated. This issue allows a user within the same Entra ID domain to obtain a local Unix session as another user by providing their own valid credentials. The flaw is located in the token validate() function, which validates domain aliases for multi-domain scenarios but fails to verify that the local part (username) of the authenticated user's User Principal Name (UPN) matches the requested account username, comparing only the domains instead of the complete usernames.
Recommendations Update to version 3.1.5. Update to version 2.3.11.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-45108

Affected Products

Himmelblau