peter bassill · operator
$ cve CVE-2020-36911 JSON

CVE-2020-36911

9.8
CRITICAL · CVSS 3.1 · EPSS 12.1% (pctl 96)

Patch early

EPSS 12.1% — above the 10% action threshold.

Description

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.07% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2026-01-13
Last modified2026-06-17

Affected (1)

VendorProduct
cobbrcovenant

References

→ the Explorer  ·  watch your stack  ·  NVD