{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/maxkey/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-69102"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MaxKey"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MaxKey"],"content_html":"\u003cp\u003eMaxKey contains an unauthorized access vulnerability (CVE-2026-69102) stemming from a hard-coded JWT signing secret within the 'application-maxkey.properties' file. This flaw permits unauthenticated attackers to forge valid JWT tokens, allowing them to bypass traditional authentication mechanisms. By submitting a forged token signed with the known static secret to the '/sign/login/jwt/trust' endpoint, an attacker can impersonate any user, including administrators. Successful exploitation grants the attacker full administrative access to the SSO platform, enabling the modification of SSO configurations and the exfiltration of downstream application secrets. This vulnerability is highly critical due to the ease of exploitation and the significant impact on centralized authentication security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe threat to organizations using MaxKey for SSO, as it allows for complete compromise of the identity provider. Successful exploitation results in full administrative access, potentially leading to unauthorized access to all downstream applications integrated via SSO, exfiltration of credentials or sensitive configuration tokens, and long-term persistent access to the organization's identity infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit all MaxKey deployments to identify and rotate the JWT signing secret found in 'application-maxkey.properties'.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the '/sign/login/jwt/trust' endpoint to known, trusted management IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the '/sign/login/jwt/trust' path, specifically looking for anomalous successful authentication attempts originating from untrusted sources.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the MaxKey project immediately upon availability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T19:49:25Z","date_published":"2026-08-11T19:49:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-maxkey-jwt-auth-bypass/","summary":"MaxKey contains a critical vulnerability due to a hard-coded JWT signing secret that allows unauthenticated attackers to forge authentication tokens and gain administrative access.","title":"MaxKey Unauthorized Access via Hard-coded JWT Signing Secret","url":"https://feed.craftedsignal.io/briefs/2026-08-maxkey-jwt-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - MaxKey","version":"https://jsonfeed.org/version/1.1"}