Vulnerability Description
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/dromara/MaxKey
- https://github.com/dromara/MaxKey/commit/6cda394ec111f03a06fb2eed0de74f787d68bd9
- https://github.com/dromara/MaxKey/issues/270
- https://www.vulncheck.com/advisories/maxkey-hard-coded-jwt-secret-unauthorized-a
FAQ
What is CVE-2026-69102?
CVE-2026-69102 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authent...
How severe is CVE-2026-69102?
CVE-2026-69102 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-69102?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.