Tag
high
advisory
CVE-2026-64623: Jovancoding Network-AI Signature Verification Bypass Leading to Remote Code Execution
4 TTPs 1 CVEJovancoding Network-AI versions before 5.13.4 are vulnerable to an improper cryptographic signature verification flaw (CVE-2026-64623) in the APSAdapter component, allowing unauthenticated attackers to bypass signature validation by submitting forged APS delegation payloads with arbitrary scopes to obtain signed permission tokens for sensitive resources, including SHELL_EXEC capabilities.
Network-AI < 5.13.4
vulnerability
rce
signature-bypass
network-ai
4t
1c
critical
advisory
Network-AI Unauthenticated Access to MCP HTTP Endpoint
2 rules 1 TTP 2 IOCsNetwork-AI is vulnerable to missing authentication on the MCP HTTP endpoint, allowing unauthenticated privileged tool calls that could lead to configuration changes and agent manipulation.
Network-AI
cwe-306
authentication-bypass
2r
1t
2i