Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 21:17
Updated : 2026-07-31 12:16
NVD link : CVE-2026-52539
Mitre link : CVE-2026-52539
CVE.ORG link : CVE-2026-52539
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
