An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2023-27001.pdf