A vulnerability identified as problematic has been detected in sigstore sigstore-java 2.0.0 . This impacts an unknown function. The manipulation leads to improper certificate validation. This vulnerability is documented as CVE-2026-48791 . The attack can be initiated remotely. There is not any exploit available. You should upgrade the affected component.