CVE-2026-88819: Siglet vulnerability
Published Sep 14, 2026
·Updated
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
Affected Software
1 affected component
Siglet=
Event History
Sep 14, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Siglet releases should be considered affected?
The issue is reported to affect both current and past versions of Siglet.