
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
| Field | Value |
|---|
| Severity | 9.1 (Critical) |
| Vector | Network |
| Affected Versions | 3.2.0 – 3.2.4 |
| Discovered By | 𝕍𝕠𝕤𝕤🥷 |
A critical misconfiguration in the SWIFT API Gateway allows an attacker to craft a JWT using the HS256 algorithm while the server expects RS256. The server incorrectly validates the token using the public RSA key as an HMAC secret, allowing an attacker to forge valid administrative tokens.
This vulnerability enables an attacker to execute administrative actions on the SWIFT gateway — including transaction approval, user management, and log tampering.
This research is for educational purposes only. Unauthorized use is prohibited.