External risk intelligence

Nimble ZTA Improper Signature Verification Allows Cloudflare Token Impersonation.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-91187

The vulnerability resides in a library specifically designed to handle Cloudflare Zero Trust authentication. Applications implementing this strategy function as identity gateways or web services that are by design public-facing to verify tokens from the internet. As it handles authentication for internet-facing endpoints, the attack surface is inherently exposed.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the nimble_zta library, which is used for Cloudflare Zero Trust authentication. An unauthenticated attacker could exploit this flaw to impersonate any service token, potentially leading to unauthorized access to sensitive systems. The main concern at this stage is confirming if your applications utilize this specific authentication method.

  • Issue allows unauthorized service token impersonation.
  • Critical for systems using Cloudflare Zero Trust.
  • Confirm if your Cloudflare authentication is affected.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can impersonate any Cloudflare service token by sending a forged JSON Web Token. This is possible because the application improperly verifies the cryptographic signature of the token, allowing the attacker's malicious token to be accepted as valid. Consequently, the attacker gains the identity of the service token, potentially leading to unauthorized access or actions within applications using this authentication method.

  • No authentication required.
  • Sends forged JWT in header.
  • Impersonates Cloudflare service tokens.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to impersonate any Cloudflare service token when applications use the Cloudflare Zero Trust authentication strategy. This occurs because the system improperly verifies cryptographic signatures, allowing a forged JWT to be accepted as a valid token, thereby granting the attacker the claims of the service token.

  • Arbitrary Cloudflare service tokens could be impersonated.
  • Forged JWTs could be accepted by the system.
  • Unauthorized access to protected resources may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects applications using the Cloudflare Zero Trust authentication strategy through the `nimble_zta` library. The primary responsibility for addressing this issue likely falls to the platform or application teams managing these services, in coordination with the security team. The first critical step is to identify all instances of the affected technology, confirm their exposure and business criticality, and then engage the accountable owner to plan a risk-based remediation.

  • Platform or application teams own remediation.
  • Verify external reachability and business criticality first.
  • Plan remediation based on identified risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the nimble_zta library?

nimble_zta is a software library for the Elixir programming language. Developers use it to simplify the process of validating Cloudflare Zero Trust authentication tokens within their web applications. It acts as an integration layer that confirms the identity of users or services connecting to systems protected by Cloudflare.

What does CWE-347 mean for CVE-2026-91187?

CWE-347 refers to Improper Verification of Cryptographic Signature. In this CVE, the code receives a digital token but fails to correctly check if the sender’s signature is authentic. Because the software ignores the failure result and treats the token as valid anyway, it incorrectly accepts forged data as legitimate.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted JSON Web Token (JWT) to an application using the vulnerable library. The attacker provides a forged token containing their own claims in the request header. If the application uses the flawed verification function, it will accept the forged token, regardless of its invalid cryptographic signature.

How relevant is this CVE to my systems?

According to Halo Surface Signal, this vulnerability is highly relevant if you run services that verify Cloudflare Zero Trust tokens, as these are typically internet-facing gateways. Because these services are designed to accept tokens from the network, the attack surface is inherently exposed. You should prioritize checking if your internet-exposed endpoints rely on nimble_zta for authentication.

What are the first steps for remediation?

Begin by auditing your dependency manifests to identify applications using nimble_zta versions 0.1.2 or older. Once you have identified these components, work with your engineering teams to determine which are public-facing or handle sensitive data. Coordinate with application owners to plan an update to a secure version of the library to resolve the signature verification flaw.

References