← Back to browse · API

CVE-2020-36911

Severity
CRITICAL
CVSS
9.3
EPSS
0.1084
Risk score
40.99
CISA KEV
No
PoC
No
Published
2026-01-13
Modified
2026-05-14
First seen
2026-08-07
Aliases
EUVD-2026-2654, GHSA-PFJR-8V62-GMM9
Products
Cobbr:Covenant 0.1.3 ≤0.5
Sources
euvd EUVD-2026-2654

Description

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

References