Unauthorized Access Vulnerability in MaxKey Authentication System by Dromara
CVE-2026-69102
9.3CRITICAL
What is CVE-2026-69102?
MaxKey is susceptible to an unauthorized access vulnerability caused by a hard-coded JWT signing secret in the application-maxkey.properties file. This flaw enables unauthenticated attackers to forge valid JWT tokens and exploit the password-skipped login endpoint. By utilizing the known default secret, attackers can create a crafted JWT token and submit it to the /sign/login/jwt/trust endpoint. If successful, they gain unauthorized access as an admin, compromising sensitive SSO application configurations and secrets of downstream applications.
Affected Version(s)
MaxKey 0 <= 4.1.11
