Vendor
critical
advisory
Hard-coded JWT Secret in Crawlab Vulnerability
2 TTPs 1 CVECrawlab versions 0.6.3 and earlier utilize a hard-coded HMAC-SHA256 secret for JWT signing, enabling unauthenticated attackers to forge administrative tokens and achieve remote code execution.
Crawlab
web-application
authentication-bypass
remote-code-execution
2t
1c
high
advisory
Authorization Bypass in Crawlab Password Change Endpoint
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability in Crawlab (CVE-2026-75103) allows authenticated users to reset the passwords of any account, enabling administrator takeover and subsequent arbitrary code execution.
Crawlab
1r
2t
1c