
🔴 Centrifugo, Cross-Tenant JWT Authentication Bypass via JWKS Cache Kid Collision, #CVE-2026-49998 (High) -DC-Jul2026-809 https://dailycve.com/centrifugo-cross-tenant-jwt-authentication-bypass-via-jwks-cache-kid-collision-cve-2026-49998-high-dc-jul2026-809/
Post summary
A high‑severity cross‑tenant JWT authentication bypass through a JWKS cache key‑ID collision (CVE‑2026‑49998) has been disclosed, but the post provides no proof‑of‑concept, exploit code, or evidence of active exploitation.
