CVE-2026-25554 | OpenSIPS up to 3.6.3 JWT authorize.c jwt_db_authorize sql injection (EUVD-2026-8694)
A vulnerability labeled as critical has been found in OpenSIPS up to 3.6.3. The affected element is the function jwt_db_authorize of the file modules/auth_jwt/authorize.c of the component JWT Handler. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-25554. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.