Record summary

CVE-2020-36911 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.1.3 to ≤ 0.5affected

Proofs of concept

1

Catalogued exploits

ExploitDBCovenant v0.5 - Remote Code Execution (RCE)ExploitDB exploitby xThazNot analyzed1 file
ExploitDB

PoC details

References

8