Improper Signature Verification (CWE-347)
CWE-347 applies when a product does not verify, or verifies incorrectly, the cryptographic signature on data. Data that should be rejected as untrusted is accepted as authentic. It is a child of Insufficient Verification of Data Authenticity (CWE-345).
About CWE-347
An attacker may gain access to sensitive data, modify application data, assume another identity or run unauthorized code.
Mitigations
- +Choose the verification algorithm from the verifier's own configuration and do not let the signed object's header select it (OWASP JWT guidance).
- +Reject unsigned tokens, such as JWTs declaring the none algorithm (OWASP).
- +Hardcode accepted algorithms and do not mix public-key signature and MAC algorithms, to avoid key type confusion (OWASP).
- +Resolve verification keys only from sources already trusted, not from keys or URLs named in the token header (OWASP).
Detection
Automated static analysis (SAST) is rated highly effective by MITRE for this weakness.
CWE-347 Vulnerabilities
6 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-5430 | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover | WSO2 | 10.0 | 0.6% | KEV | 2026-08-06 |
| CVE-2026-48558 | SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | SimpleHelp | 10.0 | 5.7% | KEV | 2026-06-12 |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Fortinet | 9.1 | 68.3% | KEV | 2025-12-09 |
| CVE-2020-2021 | PAN-OS: Authentication Bypass in SAML Authentication | Palo Alto Networks | 10.0 | 4.4% | KEV | 2020-06-29 |
| CVE-2013-3900 | WinVerifyTrust Signature Validation Vulnerability | Microsoft | 5.5 | 44.6% | KEV | 2013-12-11 |
| CVE-2026-67276 | SSH user impersonation possible in Mikrotik RouterOS | Mikrotik | 9.2 | 6.5% | 2026-09-05 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-347?→
CWE-347 is improper verification of a cryptographic signature: the product skips signature checks or performs them incorrectly.
How does CWE-347 show up in token-based authentication?→
OWASP describes cases where JWT libraries accepted unsigned tokens or confused public keys with MAC secrets. Both let forged tokens pass verification.
How many exploited vulnerabilities are classified as CWE-347?→
This database lists 6 CVE records mapped to CWE-347 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-5430, CVE-2026-48558, CVE-2025-59718.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.