Skip to main content

About CWE-347

An attacker may gain access to sensitive data, modify application data, assume another identity or run unauthorized code.

MITRE name
Improper Verification of Cryptographic Signature
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft

Mitigations

  • +Choose the verification algorithm from the verifier's own configuration and do not let the signed object's header select it (OWASP JWT guidance).
  • +Reject unsigned tokens, such as JWTs declaring the none algorithm (OWASP).
  • +Hardcode accepted algorithms and do not mix public-key signature and MAC algorithms, to avoid key type confusion (OWASP).
  • +Resolve verification keys only from sources already trusted, not from keys or URLs named in the token header (OWASP).

Detection
Automated static analysis (SAST) is rated highly effective by MITRE for this weakness.

CWE-347 Vulnerabilities

6 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
WSO210.00.6%KEV2026-08-06
CVE-2026-48558
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
SimpleHelp10.05.7%KEV2026-06-12
CVE-2025-59718
Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
Fortinet9.168.3%KEV2025-12-09
CVE-2020-2021
PAN-OS: Authentication Bypass in SAML Authentication
Palo Alto Networks10.04.4%KEV2020-06-29
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Microsoft5.544.6%KEV2013-12-11
CVE-2026-67276
SSH user impersonation possible in Mikrotik RouterOS
Mikrotik9.26.5%2026-09-05

Frequently Asked Questions

What is CWE-347?→

CWE-347 is improper verification of a cryptographic signature: the product skips signature checks or performs them incorrectly.

How does CWE-347 show up in token-based authentication?→

OWASP describes cases where JWT libraries accepted unsigned tokens or confused public keys with MAC secrets. Both let forged tokens pass verification.

How many exploited vulnerabilities are classified as CWE-347?→

This database lists 6 CVE records mapped to CWE-347 by their CVE Numbering Authority. 5 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 1 to known ransomware campaigns. Examples include CVE-2026-5430, CVE-2026-48558, CVE-2025-59718.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.