CVE-2026-81719: Insecure Plugin Signature Policy Default Warn

The plugin signature verification policy defaults or falls back to WARN instead of ENFORCE. This allows unsigned or unverifiable third-party plugins to be loaded and executed without cryptographic verification.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-81719-insecure-plugin-signature-policy-default-warn --engine opengrep

Description

The plugin signature verification policy defaults or falls back to WARN instead of ENFORCE. This allows unsigned or unverifiable third-party plugins to be loaded and executed without cryptographic verification.