An unauthenticated attacker could impersonate any user in SharePoint 2019 by using an alg:none JWT for OAuth authentication.