Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-69102: MaxKey Hard-coded JWT Secret Allows Unauthorized Access
CVE-2026-69102 · published 23 days ago
Summary
MaxKey's login system has a secret key stored in plain sight, making it easy for attackers to create fake login tokens. This allows anyone to log in as any user, including administrators, and access sensitive information. Update MaxKey to use a secure method of storing its JWT secret key.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dromara | maxkey | <= 4.1.11 |
Original advisory text
MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.
References
- https://github.com/dromara/MaxKey
- https://github.com/dromara/MaxKey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd9...
- https://github.com/dromara/MaxKey/issues/270
- https://www.vulncheck.com/advisories/maxkey-hard-coded-jwt-secret-unauthorized-a...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69102... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-69102 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Monitor software like this
Free during beta