CVE-2026-25554: OpenSIPS 3.1 <= 3.6.4 auth_jwt SQL Injection Enables JWT Authentication Bypass

Published Feb 25, 2026
·
Updated

OpenSIPS versions 3.1 before 3.6.4 containing the authjwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwtdbauthorize() function in modules/authjwt/authorize.c when dbmode is enabled and a SQL database backend is used. The function extracts the tag claim from a JWT without prior signature verification and incorporates the unescaped value directly into a SQL query. An attacker can supply a crafted JWT with a malicious tag claim to manipulate the query result and bypass JWT authentication, allowing impersonation of arbitrary identities.

Affected Software

1 affected component
OpenSIPS OpenSIPS<3.6.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenSIPS auth_jwt (versions 3.1 <= 3.6.4) to a version that resolves this vulnerability.

    Fixed in 3.6.4Patch commit 3822d33

Event History

Feb 25, 2026
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:23 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-25554?

CVE-2026-25554 is classified with a high severity due to its potential for SQL injection attacks that can lead to JWT authentication bypass.

2

How do I fix CVE-2026-25554?

To fix CVE-2026-25554, upgrade OpenSIPS to version 3.6.4 or later to eliminate the vulnerability in the auth_jwt module.

3

What versions of OpenSIPS are affected by CVE-2026-25554?

CVE-2026-25554 affects OpenSIPS versions 3.1 through 3.6.4 prior to commit 3822d33.

4

Is CVE-2026-25554 exploitable remotely?

Yes, CVE-2026-25554 is remotely exploitable, allowing attackers to execute SQL injection attacks through JWT authentication.

5

What function is vulnerable in CVE-2026-25554?

The jwt_db_authorize() function in OpenSIPS is vulnerable to SQL injection in CVE-2026-25554.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203