Skip to content
Threat Feed
critical advisory

Authentication Bypass in BotSharp via Hard-Coded JWT Secret

BotSharp versions 5.2.0 and earlier contain an authentication bypass vulnerability allowing unauthenticated attackers to forge administrative bearer tokens using a hard-coded JWT signing key.

CVE search metadata

CVE search record: CVE-2026-108860. Severity: critical. CVSS: 9.1. KEV: no. Product: BotSharp (<= 5.2.0). Brief: Authentication Bypass in BotSharp via Hard-Coded JWT Secret. Brief link: https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/

BotSharp versions 5.2.0 and earlier are affected by a critical authentication bypass vulnerability (CVE-2026-108860). The flaw resides in the WebStarter component, where a hard-coded HMAC secret key is defined within the appsettings.json file for JWT signing. This static secret, combined with predictable issuer and audience fields, permits unauthenticated remote attackers to generate valid, signed JSON Web Tokens (JWTs). By successfully forging these tokens, an attacker can impersonate any user, including accounts with administrative privileges, to bypass authorization controls on API endpoints. This vulnerability significantly impacts the confidentiality and integrity of any organization deploying BotSharp, as it allows for full unauthorized access to protected API routes without requiring valid credentials.

Impact

The vulnerability allows for complete compromise of the BotSharp application instance. Success grants attackers the ability to access, modify, or delete data through restricted API routes. There is no specific sector targeting mentioned, but any environment utilizing BotSharp as an agent orchestration framework is susceptible to full administrative takeover.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Update BotSharp deployments to a version that patches CVE-2026-108860 by removing hard-coded secrets from the configuration.
  • Audit all BotSharp appsettings.json files for the existence of hard-coded JWT signing keys.
  • Implement monitoring for anomalous or high-volume administrative actions originating from API requests, focusing on tokens with unexpected issuer or audience claims.
  • Rotate all secrets and credentials used within the BotSharp environment, as the existing hard-coded key must be considered compromised.

Immediate actions

Patch or upgrade BotSharp to a secure version

IT Operations 24h

Rotate all JWT signing keys in use within the BotSharp environment

IT Operations 24h

Mitigations

Remove or rotate hard-coded secrets in appsettings.json

immediate IT Operations

CVE-2026-108860