MEDIUM
CVE-2026-88819
CVSS
6.3
Description
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
Weakness (CWE)
CWE-290
CWE-345
EPSS Score
0.12%
Probability of exploitation in next 30 days
2.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.