Vendor
critical
advisory
MaxKey Unauthorized Access via Hard-coded JWT Signing Secret
1 rule 2 TTPs 1 CVEMaxKey contains a critical vulnerability due to a hard-coded JWT signing secret that allows unauthenticated attackers to forge authentication tokens and gain administrative access.
MaxKey
1r
2t
1c
medium
advisory
Insufficient Redirect URI Validation in MaxKey
2 TTPs 1 CVEMaxKey versions through 4.1.12 are vulnerable to OAuth 2.0 authorization code hijacking due to improper host boundary checks in the DefaultRedirectResolver component.
MaxKey
oauth
identity-management
cve-2026-67345
2t
1c