Feed/CVE-2026-4349
CVE-2026-4349MEDIUMCVSS 5.6

CVE-2026-4349

Published Mar 17, 2026·Updated Jun 17, 2026

NVD Description

A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is described as difficult. This vulnerability only affects products that are no longer supported by the maintainer.

Public Exploits & PoCs10 found

[POC] CVE-2026-43499 — CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

21

[POC] CVE-2026-43499 — CVE-2026-43499-Neo11Plus

the CVE-2026-43499 by iqooneo11

18

[POC] CVE-2026-43499 — GhostLock-Galaxy

Root your Galaxy using CVE-2026-43499

4

[POC] CVE-2026-43499 — Mi8E5-Unlocker-by-CVE-2026-43499

基于 CVE-2026-43499 的 8E5 机型自动化解锁辅助工具,仅限授权安全研究与自有设备使用。

3

[POC] CVE-2026-43499 — tcp-zerocopy-sm

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 port

2

[POC] CVE-2026-43499 — root-my-s9280

Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

2

[POC] CVE-2026-43499 — ghostlock-oneplus

GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader

2

[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-43499-S25U

Galaxy S25 Ultra SM-S938N S938NKSUACZF1 port of CVE-2026-43499

2

[POC] CVE-2026-43499 — GhostLock-5.10

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

1

[POC] CVE-2026-43499 — ghostlock-cve-2026-43499-4.19-k40

CVE-2026-43499 (GhostLock) rtmutex remove_waiter() UAF local-root PoC adapted for Qualcomm Android 4.19 kernels (Redmi K40 / Snapdragon 870 class), LD_PRELOAD based

1

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free