Junglewise Threat Intelligence

CVE-2026-90452: Reverse proxy identity provider certificate validation bypass

CVE-2026-90452 · Severity: info · CVSS 7.4 · Published 2026-09-11

Technologies: <UNKNOWN>.

Executive brief

A reverse proxy component fails to verify the SSL certificate of an identity provider service during token discovery, introspection, and credential exchange. An attacker on the network path between the proxy and identity provider could intercept these connections, forge authentication tokens, and gain unauthorized access to protected systems or services that rely on the proxy's authentication.

Technical details

This is a certificate validation bypass vulnerability in the reverse proxy's communication with the identity provider service. The vulnerable component does not verify the identity provider's server certificate during critical authentication operations (token discovery, introspection, and credential exchange), making it susceptible to man-in-the-middle (MITM) attacks. An attacker positioned on the network path between the proxy and identity provider can impersonate the identity provider service, intercept authentication requests, and issue forged tokens that are subsequently accepted by the deployment. No public exploit is currently known. Patches or remediation details are not provided in the advisory.

Affected products

  • <UNKNOWN> <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References