{"id":"CVE-2026-69102","summary":"MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust","details":"MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.","modified":"2026-08-15T09:53:25.297373Z","published":"2026-08-11T18:04:26.008Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-798"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69102.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69102.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69102"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/maxkey-hard-coded-jwt-secret-unauthorized-access-via-login-jwt-trust"},{"type":"REPORT","url":"https://github.com/dromara/MaxKey/issues/270"},{"type":"FIX","url":"https://github.com/dromara/MaxKey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97"},{"type":"PACKAGE","url":"https://github.com/dromara/MaxKey"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dromara/maxkey","events":[{"introduced":"0"},{"fixed":"6cda394ec111f03a06fb2eed0de74f787d68bd97"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"4.1.11"}]}}],"versions":["4.1.12","4.1.11","4.1.10","4.1.9","4.1.8","4.1.7","4.1.6","4.1.5","4.1.4","4.1.3","4.1.2","4.0.5","4.1.1","4.1.0","4.0.4","4.0.3","4.0.2","4.0.0","3.5.19","3.5.18","3.5.17","3.5.16","3.5.15","3.5.14","v3.5.13","3.5.12","3.5.11","v3.5.10","v3.5.9ga","v3.5.9","v3.5.8","v3.5.7","v3.5.6","v3.5.5GA","v3.5.5","v3.5.4GA","v3.5.3GA","v3.5.2GA","v3.5.1GA","v3.5.0GA","v3.5.0RC","v3.3.3GA","v3.3.2GA","v3.3.1GA","v3.3.0GA","v3.2.0","v3.2.0GA","v3.1.1GA","v3.1.0GA","v3.0.0GA","v2.9.0GA","v2.9.0RC1","v2.8.1GA","v2.8.0GA","v2.8.0RC1","v2.7.0GA","v2.6.0GA","v2.5.0GA","v2.4.0GA","v2.4.0RC2","v2.3.0GA","v2.2.0GA","v2.2.0RC2","v2.1.0RC","v2.1.0GA","v2.0.0GA","v2.0.0RC5","v2.0.0RC3","v2.0.0RC2","v2.0.0RC1","v1.4.0GA","v.1.3GA","v.1.2.1GA","v.1.2GA"],"database_specific":{"vanir_signatures":[{"digest":{"line_hashes":["316295808544295588977146604222686796656","321060900238788086161250759683054431411","316316797826539088401439469128250070478","329451037456927361781849977912346516058","114917186409310803883486502663944765214","182763817859816843292737369197360719596","41232952926791439905537567345625281480"],"threshold":0.9},"id":"CVE-2026-69102-539151dc","signature_type":"Line","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97","target":{"file":"maxkey-commons/maxkey-core/src/main/java/org/dromara/maxkey/configuration/LoginConfig.java"},"deprecated":false},{"id":"CVE-2026-69102-7f9f29eb","signature_type":"Line","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97","target":{"file":"maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"},"deprecated":false,"digest":{"line_hashes":["333524777674976869929984791959345909990","99189409608023404898015121156737136152","190047736360910895288384376292862667336","276241082288939276496128707919703655238","149487849915379409245630398832400070792","106064426668957751927176103443012599314","156974218020019244522060855600821548396","328570903585386194056813607544247624293","309328722120820164691317022910186751719","173667512989825578249420619374000864360","307700070672960970570098197302571842132","278621694740967993166967176085802532877","305561096284997663938523564899879160029","288486707535169713252205002848236493813","33262244769914820629504868753148927314","153315870925049464235230967408750815966","272413352845883650352363144212544543870","51302100271184346866421566011333222456","229734464933136546356876987412553218093","129097295697261687717972604010890621074","314698911704919727852292279742504276172","182246878834770802516679941441696768758","264927910949286178680212625494669797343","316155488377937215290167657663846467342","272095225429736575167015751310869876204","242424675071367118686879422008000518073","11542186202620461793191511143458813721","188490871074029366882783101472078316435","90686152438171263010899691423855768860","153935312673320974639859557363520948154","155527584281896215495242601789433825718","33262244769914820629504868753148927314","153315870925049464235230967408750815966","272413352845883650352363144212544543870","51302100271184346866421566011333222456","229734464933136546356876987412553218093","129097295697261687717972604010890621074","314698911704919727852292279742504276172","182246878834770802516679941441696768758","59951005865020475708163628689199909912","38871585471119129100480103305775788645","75042342061971343991682542689822715250"],"threshold":0.9}},{"id":"CVE-2026-69102-8dad12e4","signature_type":"Function","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97","target":{"file":"maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java","function":"jwt"},"deprecated":false,"digest":{"function_hash":"163860561400490043535991452364616924133","length":666}},{"target":{"file":"maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java","function":"jwtTrust"},"deprecated":false,"digest":{"function_hash":"254378398472236124599431557311954846624","length":663},"id":"CVE-2026-69102-ad26e43e","signature_type":"Function","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69102.json","vanir_signatures_modified":"2026-08-15T09:53:25Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}