# CVE-2026-42869

## Summary

- **CVE ID:** CVE-2026-42869
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-287, CWE-522, CWE-798
- **Published:** May 11, 2026
- **Last Modified:** May 12, 2026

## Description

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrary admin-scoped JWTs and gain full control of the application and every security tool it manages without any credentials. This vulnerability is fixed in 0.1.57.

## Affected Products

- socfortress — CoPilot (< 0.1.57)

## References

- [CNA](https://github.com/socfortress/CoPilot/security/advisories/GHSA-4gxj-hw3c-3x2x)
- [CNA](https://github.com/socfortress/CoPilot/pull/814)
- [CNA](https://github.com/socfortress/CoPilot/commit/4640511a0cf2e7b144a71375b5b349a8318cb186)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 37.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._