CVE-2026-90945

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 18:20

Updated : 2026-09-14 18:20


NVD link : CVE-2026-90945

Mitre link : CVE-2026-90945

CVE.ORG link : CVE-2026-90945


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key