Detects the All-in-One Microsoft 365 & Entra ID SSO Login plugin at version 2.2.5 or earlier, where JWT tokens from the browser are accepted without cryptographic signature verification. An unauthenticated attacker can forge a token with any user's email and log in as administrator.
Is your app exploitable through CVE-2026-2628?
Scan your domain free