CVE-2026-105161
Received Received - Intake

Improper Cryptographic Signature Verification in aiir

Vulnerability report for CVE-2026-105161, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulDB

Description

A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
invariant-systems-ai aiir to 1.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the aiir component up to version 1.7.0, specifically in the Policy Gate Handler. It allows remote attackers to bypass cryptographic signature verification due to improper checks, causing the system to incorrectly accept unverified inputs as valid. The flaw causes a 'fail-open' behavior where security controls are not enforced.

Detection Guidance

Detect this vulnerability by checking the version of aiir installed on your system. If it is below 1.7.0, the system is vulnerable. Use commands like 'aiir --version' or inspect package managers for installed versions.

Impact Analysis

This vulnerability could allow attackers to bypass security controls and treat unsigned or forged receipts as legitimate. This affects integrity by enabling unauthorized bypass of verification, potentially leading to acceptance of malicious or tampered inputs.

Compliance Impact

This vulnerability may impact compliance by undermining integrity controls required by standards like GDPR and HIPAA. Failing to enforce cryptographic verification could result in non-compliance with data integrity and security requirements.

Mitigation Strategies

Upgrade aiir to version 1.7.0 or later immediately. Since no workarounds exist for earlier versions, updating is the only mitigation. Ensure all verification paths enforce cryptographic checks and fail closed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105161. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart