CVE-2026-90945
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.53%
- CWE
- CWE-321
- Published
- 2026-09-14
- Last modified
- 2026-09-16
Affected products
- crawlab-team crawlab
Weakness type
Related vulnerabilities
- CVE-2025-30406 — Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
- CVE-2025-13316 — Hard-coded encryption keys in Twonky Server
- CVE-2025-34217 — Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
- CVE-2025-12599 — Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)
- CVE-2026-25505 — Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
- CVE-2026-22906 — Hardcoded Key Allows Credential Disclosure
- CVE-2025-8625 — Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution
- CVE-2025-41702 — egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass