CVE-2026-11618: Taier Improper Auth Interceptor
The preHandle method checks if an authentication token is missing or blank but returns true immediately without validating its cryptographic integrity or decrypting it. This allows an attacker to bypass authentication by providing any arbitrary non-blank string. Validate or decrypt the token before returning true.
greprules fetch cve-2026-11618-taier-improper-auth-interceptor --engine opengrepDescription
The preHandle method checks if an authentication token is missing or blank but returns true immediately without validating its cryptographic integrity or decrypting it. This allows an attacker to bypass authentication by providing any arbitrary non-blank string. Validate or decrypt the token before returning true.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.