Unauthorized Access Vulnerability in MaxKey Authentication System by Dromara
CVE-2026-69102

9.3CRITICAL

Key Information:

Vendor

Dromara

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-69102?

MaxKey is susceptible to an unauthorized access vulnerability caused by a hard-coded JWT signing secret in the application-maxkey.properties file. This flaw enables unauthenticated attackers to forge valid JWT tokens and exploit the password-skipped login endpoint. By utilizing the known default secret, attackers can create a crafted JWT token and submit it to the /sign/login/jwt/trust endpoint. If successful, they gain unauthorized access as an admin, compromising sensitive SSO application configurations and secrets of downstream applications.

Affected Version(s)

MaxKey 0 <= 4.1.11

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lza, Fiona
.