{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/duplicati--2.2.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Duplicati (\u003c= 2.2.0.3)"],"_cs_severities":["high"],"_cs_tags":["webapps","privilege-escalation","jwt"],"_cs_type":"advisory","_cs_vendors":["Duplicati"],"content_html":"\u003cp\u003eResearchers have disclosed a vulnerability in Duplicati 2.2.0.3 (and earlier versions) where a case-sensitive guard bypass in the settings API allows for the unauthorized retrieval of JWT configuration data. The application contains a protective mechanism intended to prevent access to the 'jwt-config' endpoint. However, by requesting the endpoint using PascalCase ('JWTConfig'), attackers can bypass this guard.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker the SigningKey, Authority, and Audience strings. Using this information, an attacker can construct and sign their own long-lived administrative JWTs. This enables the attacker to gain full administrative control over the Duplicati instance, including the ability to modify backup configurations and access protected data. This vulnerability was reported via responsible disclosure and is addressed in subsequent commits to the master branch.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a valid, low-privileged session with the Duplicati web interface.\u003c/li\u003e\n\u003cli\u003eAttacker discovers that requests to /api/v1/serversetting/jwt-config are blocked by a security guard.\u003c/li\u003e\n\u003cli\u003eAttacker submits a request to /api/v1/serversetting/JWTConfig, successfully bypassing the case-sensitive filter.\u003c/li\u003e\n\u003cli\u003eThe server returns a JSON response containing the SigningKey, Authority, and Audience values.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the extracted SigningKey to generate a new JSON Web Token (JWT) with elevated administrative claims.\u003c/li\u003e\n\u003cli\u003eAttacker replaces their existing session token with the forged administrative JWT.\u003c/li\u003e\n\u003cli\u003eAttacker accesses administrative endpoints, such as /api/v1/serversetting/AllowedHostnames, using the forged token to verify full privilege escalation.\u003c/li\u003e\n\u003cli\u003eAttacker proceeds to manage backups, export keys, or exfiltrate sensitive data via the administrative interface.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full administrative compromise of the Duplicati server. This allows an attacker to manipulate backup tasks, steal backup data, and potentially execute further actions within the context of the host operating system, depending on the server's deployment and permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Duplicati instances to the latest available version beyond 2.2.0.3 immediately to patch the endpoint guard bypass.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for requests to the /api/v1/serversetting/ endpoint containing non-standard case variations of 'jwt-config'.\u003c/li\u003e\n\u003cli\u003eImplement strictly scoped network access controls to the Duplicati web interface to minimize exposure to untrusted users.\u003c/li\u003e\n\u003cli\u003eRotate the JWT SigningKey if there is any indication that the instance has been accessed by unauthorized parties.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T14:54:16Z","date_published":"2026-08-17T14:54:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-duplicati-jwt-leak/","summary":"An unpatched vulnerability in Duplicati 2.2.0.3 allows authenticated attackers to bypass security guards and extract JWT signing keys to forge administrative tokens.","title":"Duplicati JWT Signing Key Exposure via Guard Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-duplicati-jwt-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Duplicati (\u003c= 2.2.0.3)","version":"https://jsonfeed.org/version/1.1"}