CVE-2026-33746Disclosure(convoypanel / convoy)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch convoypanel convoy systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature of JWT tokens. While the method configured a symmetric HMAC-SHA256 signer via lcobucci/jwt, it only validated time-based claims (exp, nbf, iat) using the StrictValidAt constraint. The SignedWith constraint was not included in the validation step. This means an attacker could forge or tamper with JWT token payloads — such as modifying the user_uuid claim — and the token would be accepted as valid, as long as the time-based claims were satisfied. This directly impacts the SSO authentication flow (LoginController::authorizeToken), allowing an attacker to authenticate as any user by crafting a token with an arbitrary user_uuid. This issue has been patched in version 4.5.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • convoy

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-02); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
convoy

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-02: 3Mentions · 2026-04-03: 1Mentions · 2026-04-07: 2Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-02: 3Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-11: 104-0204-0304-0704-11
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
General
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-023
Disclosure2Patch1
2026-04-031
Disclosure1
2026-04-072
General1Patch1
2026-04-111
General1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.8 CVSS flaw in Convoy (CVE-2026-33746) allows unauthenticated admin access via forged JWTs. Update to v4.5.1 immediately to secure your KVM. #Convoy #CyberSecurity #InfoSec #KVMSecurity #JWTBypass #ServerManagement #BugBounty https://securityonline.info/convoy-kvm-vulnerability-jwt-authentication-bypass-cve-2026-33746/ https://t.co/gT3Vz52O29

    Post summary

    Convoy KVM’s CVE-2026-33746 is a critical 9.8 CVSS flaw that allows unauthenticated admin access via forged JWTs; users are urged to upgrade to v4.5.1 immediately.

    13032465
    12.3K followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-33746 · NIST 9.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33746

    Post summary

    The text cites CVE-2026-33746 with a high CVSS score of 9.8/10, but provides no further details on exploitation or remediation.

    1000028
    1 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33746: Convoy KVM Panel Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04bwGxW0

    Post summary

    The text references CVE-2026-33746 as an authentication bypass in Convoy KVM Panel, but provides no further detail on PoC, exploit, or remediation steps.

    0000029
    28 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33746 - Critical Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cryptographic signature... https://www.thehackerwire.com/vulnerability/CVE-2026-33746/ https://t.co/gZTQSk6BeI

    Post summary

    The tweet announces CVE-2026-33746 as a critical flaw in Convoy’s JWT authentication, providing technical details but no exploits, patches, or evidence of active use.

    0000044
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33746: CRITICAL] Security vulnerability in Convoy KVM server management panel versions 3.9.0-beta to 4.5.0 allows attackers to forge JWT tokens and authenticate as any user. Patch available in vers...#cve,CVE-2026-33746,#cybersecurity https://cvefind.com/CVE-2026-33746

    Post summary

    The post highlights a critical CVE-2026-33746 in Convoy KVM server management panel that permits JWT forging and user impersonation, and notes that a patch is available.

    0000029
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33746 Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did not verify the cr… https://www.cve.org/CVERecord?id=CVE-2026-33746

    Post summary

    CVE-2026-33746 is disclosed as a JWT verification flaw in Convoy KVM panel versions 3.9.0-beta through 4.5.1, with technical details presented but no mention of PoCs, exploits, or patches.

    0000064
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33746: Convoy: JWT Signature Verificati... JWT signature validation completely bypassed - forge any user_uuid claim and own the entire hosting panel with zero aut... https://zerodaysignal.com/vulnerability/CVE-2026-33746 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The message announces CVE-2026-33746, describing a JWT signature bypass in Convoy that lets attackers forge user UUIDs to gain full control of the hosting panel, and links to a site for further details.

    0000049
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appconvoypanelconvoy---

Explore more