Authentication Bypass in BotSharp via Hard-Coded JWT Secret
BotSharp versions 5.2.0 and earlier contain an authentication bypass vulnerability allowing unauthenticated attackers to forge administrative bearer tokens using a hard-coded JWT signing key.
CVE search metadata
CVE search record: CVE-2026-108860. Severity: critical. CVSS: 9.1. KEV: no. Product: BotSharp (<= 5.2.0). Brief: Authentication Bypass in BotSharp via Hard-Coded JWT Secret. Brief link: https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/
BotSharp versions 5.2.0 and earlier are affected by a critical authentication bypass vulnerability (CVE-2026-108860). The flaw resides in the WebStarter component, where a hard-coded HMAC secret key is defined within the appsettings.json file for JWT signing. This static secret, combined with predictable issuer and audience fields, permits unauthenticated remote attackers to generate valid, signed JSON Web Tokens (JWTs). By successfully forging these tokens, an attacker can impersonate any user, including accounts with administrative privileges, to bypass authorization controls on API endpoints. This vulnerability significantly impacts the confidentiality and integrity of any organization deploying BotSharp, as it allows for full unauthorized access to protected API routes without requiring valid credentials.
Impact
The vulnerability allows for complete compromise of the BotSharp application instance. Success grants attackers the ability to access, modify, or delete data through restricted API routes. There is no specific sector targeting mentioned, but any environment utilizing BotSharp as an agent orchestration framework is susceptible to full administrative takeover.
Recommendation
Prioritized, concrete actions for detection engineering teams:
- Update BotSharp deployments to a version that patches CVE-2026-108860 by removing hard-coded secrets from the configuration.
- Audit all BotSharp appsettings.json files for the existence of hard-coded JWT signing keys.
- Implement monitoring for anomalous or high-volume administrative actions originating from API requests, focusing on tokens with unexpected issuer or audience claims.
- Rotate all secrets and credentials used within the BotSharp environment, as the existing hard-coded key must be considered compromised.
Immediate actions
Patch or upgrade BotSharp to a secure version
Rotate all JWT signing keys in use within the BotSharp environment
Mitigations
Remove or rotate hard-coded secrets in appsettings.json
CVE-2026-108860