{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-90945", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-09-14T11:34:24.687Z", "datePublished": "2026-09-14T17:52:06.173Z", "dateUpdated": "2026-09-14T17:52:06.173Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-09-14T17:52:06.173Z" }, "datePublic": "2026-06-13T00:00:00.000Z", "title": "Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret", "descriptions": [ { "lang": "en", "value": "Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Use of Hard-coded Cryptographic Key", "cweId": "CWE-321", "type": "CWE" } ] } ], "affected": [ { "vendor": "crawlab-team", "product": "crawlab", "defaultStatus": "unaffected", "versions": [ { "version": "0", "lessThanOrEqual": "0.6.3", "status": "affected", "versionType": "custom" } ], "repo": "https://github.com/crawlab-team/crawlab" } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 9.3, "baseSeverity": "CRITICAL" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL" } } ], "references": [ { "url": "https://github.com/crawlab-team/crawlab/issues/1622", "tags": [ "issue-tracking" ], "name": "GitHub Issue #1622" }, { "url": "https://github.com/crawlab-team/crawlab", "tags": [ "product" ] }, { "url": "https://github.com/crawlab-team/crawlab/blob/0485310def8b4f31ea20997846a8d5e7dfc681e5/core/user/service_v2.go", "tags": [ "technical-description" ], "name": "core/user/service_v2.go at 0485310" }, { "url": "https://github.com/crawlab-team/crawlab-core/blob/main/user/service.go", "tags": [ "technical-description" ], "name": "crawlab-core user/service.go, the module vendored at v0.6.3" }, { "name": "VulnCheck Advisory: Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/crawlab-through-0.6.3-authentication-bypass-via-hard-coded-jwt-secret" } ], "credits": [ { "lang": "en", "value": "George Chen", "type": "reporter" } ], "x_generator": { "engine": "vulncheck-endgame" } } } }