{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/botsharp--5.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:botsharp:botsharp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-108860"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BotSharp (\u003c= 5.2.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BotSharp"],"content_html":"\u003cp\u003eBotSharp versions 5.2.0 and earlier are affected by a critical authentication bypass vulnerability (CVE-2026-108860). The flaw resides in the WebStarter component, where a hard-coded HMAC secret key is defined within the appsettings.json file for JWT signing. This static secret, combined with predictable issuer and audience fields, permits unauthenticated remote attackers to generate valid, signed JSON Web Tokens (JWTs). By successfully forging these tokens, an attacker can impersonate any user, including accounts with administrative privileges, to bypass authorization controls on API endpoints. This vulnerability significantly impacts the confidentiality and integrity of any organization deploying BotSharp, as it allows for full unauthorized access to protected API routes without requiring valid credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for complete compromise of the BotSharp application instance. Success grants attackers the ability to access, modify, or delete data through restricted API routes. There is no specific sector targeting mentioned, but any environment utilizing BotSharp as an agent orchestration framework is susceptible to full administrative takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate BotSharp deployments to a version that patches CVE-2026-108860 by removing hard-coded secrets from the configuration.\u003c/li\u003e\n\u003cli\u003eAudit all BotSharp appsettings.json files for the existence of hard-coded JWT signing keys.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for anomalous or high-volume administrative actions originating from API requests, focusing on tokens with unexpected issuer or audience claims.\u003c/li\u003e\n\u003cli\u003eRotate all secrets and credentials used within the BotSharp environment, as the existing hard-coded key must be considered compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-11T16:02:34Z","date_published":"2026-10-11T16:02:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/","summary":"BotSharp versions 5.2.0 and earlier contain an authentication bypass vulnerability allowing unauthenticated attackers to forge administrative bearer tokens using a hard-coded JWT signing key.","title":"Authentication Bypass in BotSharp via Hard-Coded JWT Secret","url":"https://feed.craftedsignal.io/briefs/2026-10-botsharp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - BotSharp (\u003c= 5.2.0)","version":"https://jsonfeed.org/version/1.1"}