Description
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Cryptographic Signature Bypass
Action: Apply Patch
AI Analysis

Impact

A flaw exists in the Policy Gate Handler of invariant-systems-ai aiir version 1.7.0 and earlier, where an unknown function allows an attacker to manipulate input and cause the component to improperly verify cryptographic signatures. This results in a failure to detect forged or tampered policy data, potentially granting the attacker unauthorized actions within the system. The vulnerability is classified as a moderate severity, with a CVSS score of 6.9, and does not appear in the CISA KEV catalog.

Affected Systems

Products affected are invariant-systems-ai aiir up to and including version 1.7.0. The vendor has discontinued support for these releases and the repository is no longer publicly available.

Risk and Exploitability

The exploit is remote, allowing any network user to craft a request that bypasses signature verification. There is no publicly documented exploit code yet, and the EPSS score is not available. The CVSS score of 6.9 indicates that while the vulnerability can be used to gain unauthorized access or privileges, it requires successful remote exploitation and relies on a specific vulnerability in a cryptographic verification routine.

Generated by OpenCVE AI on October 4, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a newer, supported release of invariant-systems-ai aiir, or seek a vendor-supplied patch if available.
  • If no update exists, apply additional application‑level authentication controls that do not rely on the flawed signature check, such as enforcing role‑based access or mandatory integrity checks on policy payloads.
  • Monitor network traffic for attempts to forge policy requests or bypass signature validation, and log any suspicious activity for further analysis.

Generated by OpenCVE AI on October 4, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.
Title invariant-systems-ai aiir Policy Gate signature verification
First Time appeared Invariant-systems-ai
Invariant-systems-ai aiir
Weaknesses CWE-345
CWE-347
CPEs cpe:2.3:a:invariant-systems-ai:aiir:*:*:*:*:*:*:*:*
Vendors & Products Invariant-systems-ai
Invariant-systems-ai aiir
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Invariant-systems-ai Aiir
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T16:30:10.216Z

Reserved: 2026-10-04T03:13:29.438Z

Link: CVE-2026-105161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T18:16:33.560

Modified: 2026-10-04T18:16:33.560

Link: CVE-2026-105161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:30:17Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature