CVE-2026-27962
Authlib is a Python library for OAuth and OpenID Connect. A flaw in its JWS implementation lets attackers forge JWT tokens that bypass authentication. The issue is fixed in version 1.6.9.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Authlib library, versions prior to 1.6.9, used in Python applications that implement OAuth or OpenID Connect.
Real-world impact
An attacker can create a forged token that the server accepts as valid, allowing them to impersonate any user or gain unauthorized access to protected resources.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability is exploitable over the network, requires no authentication, and lets an attacker completely bypass authentication and authorization, causing complete compromise of confidentiality and integrity.
What to do about it
- 01Upgrade Authlib to version 1.6.9 or later.
NVD-referenced vendor advisory
Timeline
- Mar 16, 2026 · Mar 16, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 16d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/authlib/authlib/commit/a5d4…patch
- github.com/authlib/authlib/releases/ta…productrelease notes
- github.com/authlib/authlib/security/ad…exploitmitigationvendor advisory
- access.redhat.com/errata/RHSA-2026:19375
- access.redhat.com/errata/RHSA-2026:24853
- access.redhat.com/errata/RHSA-2026:48085
- access.redhat.com/errata/RHSA-2026:5665
- access.redhat.com/errata/RHSA-2026:7314
- access.redhat.com/security/cve/CVE-2026-27962
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…