MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69102.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-798"
]
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"316295808544295588977146604222686796656",
"321060900238788086161250759683054431411",
"316316797826539088401439469128250070478",
"329451037456927361781849977912346516058",
"114917186409310803883486502663944765214",
"182763817859816843292737369197360719596",
"41232952926791439905537567345625281480"
],
"threshold": 0.9
},
"id": "CVE-2026-69102-539151dc",
"target": {
"file": "maxkey-commons/maxkey-core/src/main/java/org/dromara/maxkey/configuration/LoginConfig.java"
},
"source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"333524777674976869929984791959345909990",
"99189409608023404898015121156737136152",
"190047736360910895288384376292862667336",
"276241082288939276496128707919703655238",
"149487849915379409245630398832400070792",
"106064426668957751927176103443012599314",
"156974218020019244522060855600821548396",
"328570903585386194056813607544247624293",
"309328722120820164691317022910186751719",
"173667512989825578249420619374000864360",
"307700070672960970570098197302571842132",
"278621694740967993166967176085802532877",
"305561096284997663938523564899879160029",
"288486707535169713252205002848236493813",
"33262244769914820629504868753148927314",
"153315870925049464235230967408750815966",
"272413352845883650352363144212544543870",
"51302100271184346866421566011333222456",
"229734464933136546356876987412553218093",
"129097295697261687717972604010890621074",
"314698911704919727852292279742504276172",
"182246878834770802516679941441696768758",
"264927910949286178680212625494669797343",
"316155488377937215290167657663846467342",
"272095225429736575167015751310869876204",
"242424675071367118686879422008000518073",
"11542186202620461793191511143458813721",
"188490871074029366882783101472078316435",
"90686152438171263010899691423855768860",
"153935312673320974639859557363520948154",
"155527584281896215495242601789433825718",
"33262244769914820629504868753148927314",
"153315870925049464235230967408750815966",
"272413352845883650352363144212544543870",
"51302100271184346866421566011333222456",
"229734464933136546356876987412553218093",
"129097295697261687717972604010890621074",
"314698911704919727852292279742504276172",
"182246878834770802516679941441696768758",
"59951005865020475708163628689199909912",
"38871585471119129100480103305775788645",
"75042342061971343991682542689822715250"
],
"threshold": 0.9
},
"id": "CVE-2026-69102-7f9f29eb",
"target": {
"file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
},
"source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 666.0,
"function_hash": "163860561400490043535991452364616924133"
},
"id": "CVE-2026-69102-8dad12e4",
"target": {
"function": "jwt",
"file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
},
"source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 663.0,
"function_hash": "254378398472236124599431557311954846624"
},
"id": "CVE-2026-69102-ad26e43e",
"target": {
"function": "jwtTrust",
"file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
},
"source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69102.json"
"2026-08-15T09:53:25Z"