Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-52539: Outstatic CMS <= 2.1.9: Hardcoded Secret Exposes Admin Access
CVE-2026-52539 · published 1 month ago
Summary
Outstatic CMS versions up to 2.1.9 contain a secret key in the code. This means that anyone can access the admin section without a password. To fix this, update to the latest version or set a custom secret key in the OST_TOKEN_SECRET environment variable.
Original advisory text
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible ...
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published30 Jul 2026
Updated25 Sep 2026
First seen30 Jul 2026
Track software like this
Free during beta