Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dromara
Dromara maxkey |
|
| Vendors & Products |
Dromara
Dromara maxkey |
Tue, 11 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets. | |
| Title | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T16:58:32.371Z
Reserved: 2026-08-03T10:44:14.336Z
Link: CVE-2026-69102
Updated: 2026-08-12T16:10:16.871Z
Status : Received
Published: 2026-08-11T18:18:17.587
Modified: 2026-08-12T17:17:30.880
Link: CVE-2026-69102
No data.
OpenCVE Enrichment
Updated: 2026-08-12T21:00:04Z