Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs | |
| Title | Missing JSON Web Token signature validation in Otalio Ship Property Management System | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2026-08-18T18:52:14.404Z
Reserved: 2025-08-19T19:19:50.465Z
Link: CVE-2025-9210
Updated: 2026-08-18T18:52:11.085Z
Status : Received
Published: 2026-08-18T19:16:43.650
Modified: 2026-08-18T19:16:43.650
Link: CVE-2025-9210
No data.
OpenCVE Enrichment
Updated: 2026-08-18T20:15:04Z