<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:botsharp:botsharp:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abotsharpbotsharp/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 16:02:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abotsharpbotsharp/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in BotSharp via Hard-Coded JWT Secret</title><link>https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/</link><pubDate>Sun, 11 Oct 2026 16:02:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/</guid><description>BotSharp versions 5.2.0 and earlier contain an authentication bypass vulnerability allowing unauthenticated attackers to forge administrative bearer tokens using a hard-coded JWT signing key.</description><content:encoded><![CDATA[<p>BotSharp versions 5.2.0 and earlier are affected by a critical authentication bypass vulnerability (CVE-2026-108860). The flaw resides in the WebStarter component, where a hard-coded HMAC secret key is defined within the appsettings.json file for JWT signing. This static secret, combined with predictable issuer and audience fields, permits unauthenticated remote attackers to generate valid, signed JSON Web Tokens (JWTs). By successfully forging these tokens, an attacker can impersonate any user, including accounts with administrative privileges, to bypass authorization controls on API endpoints. This vulnerability significantly impacts the confidentiality and integrity of any organization deploying BotSharp, as it allows for full unauthorized access to protected API routes without requiring valid credentials.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for complete compromise of the BotSharp application instance. Success grants attackers the ability to access, modify, or delete data through restricted API routes. There is no specific sector targeting mentioned, but any environment utilizing BotSharp as an agent orchestration framework is susceptible to full administrative takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Update BotSharp deployments to a version that patches CVE-2026-108860 by removing hard-coded secrets from the configuration.</li>
<li>Audit all BotSharp appsettings.json files for the existence of hard-coded JWT signing keys.</li>
<li>Implement monitoring for anomalous or high-volume administrative actions originating from API requests, focusing on tokens with unexpected issuer or audience claims.</li>
<li>Rotate all secrets and credentials used within the BotSharp environment, as the existing hard-coded key must be considered compromised.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>