CVE-2026-79575
Deferred Deferred - Pending Action

JWT Secret Brute Force in yfexam-exam

Vulnerability report for CVE-2026-79575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: MITRE

Description

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in yfexam-exam v2.0 involves the JWT signing secret being generated using the username and current month instead of a secure random server-side key. This weak derivation method allows attackers to predict or brute force the secret easily.

Detection Guidance

This vulnerability can be detected by checking if the JWT signing secret in yfexam-exam v2.0 is derived from the username and current month. Inspect the application's configuration or source code for JWT secret generation logic. No specific commands are provided in the context.

Impact Analysis

An attacker could forge valid JWT tokens by brute forcing the predictable secret. This could grant unauthorized access to sensitive exam data, allow manipulation of exam results, or enable impersonation of users within the system.

Compliance Impact

This vulnerability likely violates GDPR's requirement for secure processing of personal data and HIPAA's safeguards for protected health information. It could lead to unauthorized data exposure, breaching confidentiality and integrity requirements.

Mitigation Strategies

Immediately update yfexam-exam to a patched version that uses a random server-side key for JWT signing. If no patch is available, disable JWT authentication or implement a custom signing secret that is not derived from predictable values.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart