CVE-2026-69102

Source
https://cve.org/CVERecord?id=CVE-2026-69102
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69102.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-69102
Published
2026-08-11T18:04:26.008Z
Modified
2026-08-15T09:53:25.297373Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust
Details

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69102.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-798"
    ]
}
References

Affected packages

Git / github.com/dromara/maxkey

Affected ranges

Type
GIT
Repo
https://github.com/dromara/maxkey
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.1.11"
        }
    ]
}

Affected versions

3.*
3.5.11
3.5.12
3.5.14
3.5.15
3.5.16
3.5.17
3.5.18
3.5.19
4.*
4.0.0
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.10
4.1.11
4.1.12
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
v.*
v.1.2.1GA
v.1.2GA
v.1.3GA
v1.*
v1.4.0GA
v2.*
v2.0.0GA
v2.0.0RC1
v2.0.0RC2
v2.0.0RC3
v2.0.0RC5
v2.1.0GA
v2.1.0RC
v2.2.0GA
v2.2.0RC2
v2.3.0GA
v2.4.0GA
v2.4.0RC2
v2.5.0GA
v2.6.0GA
v2.7.0GA
v2.8.0GA
v2.8.0RC1
v2.8.1GA
v2.9.0GA
v2.9.0RC1
v3.*
v3.0.0GA
v3.1.0GA
v3.1.1GA
v3.2.0
v3.2.0GA
v3.3.0GA
v3.3.1GA
v3.3.2GA
v3.3.3GA
v3.5.0GA
v3.5.0RC
v3.5.10
v3.5.13
v3.5.1GA
v3.5.2GA
v3.5.3GA
v3.5.4GA
v3.5.5
v3.5.5GA
v3.5.6
v3.5.7
v3.5.8
v3.5.9
v3.5.9ga

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "316295808544295588977146604222686796656",
                "321060900238788086161250759683054431411",
                "316316797826539088401439469128250070478",
                "329451037456927361781849977912346516058",
                "114917186409310803883486502663944765214",
                "182763817859816843292737369197360719596",
                "41232952926791439905537567345625281480"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-69102-539151dc",
        "target": {
            "file": "maxkey-commons/maxkey-core/src/main/java/org/dromara/maxkey/configuration/LoginConfig.java"
        },
        "source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "333524777674976869929984791959345909990",
                "99189409608023404898015121156737136152",
                "190047736360910895288384376292862667336",
                "276241082288939276496128707919703655238",
                "149487849915379409245630398832400070792",
                "106064426668957751927176103443012599314",
                "156974218020019244522060855600821548396",
                "328570903585386194056813607544247624293",
                "309328722120820164691317022910186751719",
                "173667512989825578249420619374000864360",
                "307700070672960970570098197302571842132",
                "278621694740967993166967176085802532877",
                "305561096284997663938523564899879160029",
                "288486707535169713252205002848236493813",
                "33262244769914820629504868753148927314",
                "153315870925049464235230967408750815966",
                "272413352845883650352363144212544543870",
                "51302100271184346866421566011333222456",
                "229734464933136546356876987412553218093",
                "129097295697261687717972604010890621074",
                "314698911704919727852292279742504276172",
                "182246878834770802516679941441696768758",
                "264927910949286178680212625494669797343",
                "316155488377937215290167657663846467342",
                "272095225429736575167015751310869876204",
                "242424675071367118686879422008000518073",
                "11542186202620461793191511143458813721",
                "188490871074029366882783101472078316435",
                "90686152438171263010899691423855768860",
                "153935312673320974639859557363520948154",
                "155527584281896215495242601789433825718",
                "33262244769914820629504868753148927314",
                "153315870925049464235230967408750815966",
                "272413352845883650352363144212544543870",
                "51302100271184346866421566011333222456",
                "229734464933136546356876987412553218093",
                "129097295697261687717972604010890621074",
                "314698911704919727852292279742504276172",
                "182246878834770802516679941441696768758",
                "59951005865020475708163628689199909912",
                "38871585471119129100480103305775788645",
                "75042342061971343991682542689822715250"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-69102-7f9f29eb",
        "target": {
            "file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
        },
        "source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 666.0,
            "function_hash": "163860561400490043535991452364616924133"
        },
        "id": "CVE-2026-69102-8dad12e4",
        "target": {
            "function": "jwt",
            "file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
        },
        "source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 663.0,
            "function_hash": "254378398472236124599431557311954846624"
        },
        "id": "CVE-2026-69102-ad26e43e",
        "target": {
            "function": "jwtTrust",
            "file": "maxkey-authentications/maxkey-authentication-provider/src/main/java/org/dromara/maxkey/authn/support/jwt/HttpJwtEntryPoint.java"
        },
        "source": "https://github.com/dromara/maxkey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd97",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69102.json"
vanir_signatures_modified
"2026-08-15T09:53:25Z"