CVE-2026-107177
Awaiting Analysis Awaiting Analysis - Queue

Hardcoded Cryptographic Key in Express Gateway

Vulnerability report for CVE-2026-107177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ExpressGateway express-gateway 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1394 The product uses a default cryptographic key for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Express Gateway through 1.16.11 has a hardcoded cryptographic key vulnerability. The default 'sensitiveKey' is used as the cipherKey, allowing attackers with datastore access (like Redis) to decrypt stored OAuth 2.0 token secrets. This enables them to obtain valid bearer tokens for any user by combining decrypted tokens with stored token IDs.

Detection Guidance

Check if Express Gateway is using the default hardcoded cryptographic key 'sensitiveKey' in its configuration files. Inspect system.config.yml for the presence of cipherKey: 'sensitiveKey' and algorithm: aes256. Verify if Redis datastore access is enabled and if tokenEncrypted values are stored.

Impact Analysis

Attackers could gain unauthorized access to user accounts by decrypting OAuth tokens. This could lead to data breaches, account takeover, or unauthorized actions on behalf of users. The impact depends on the system's sensitivity and the data exposed through the tokens.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR (data protection) and HIPAA (health data security) due to unauthorized access to sensitive data. It may result in violations of confidentiality requirements and failure to protect personal or health information adequately.

Mitigation Strategies

Replace the hardcoded 'sensitiveKey' with a strong, randomly generated key loaded from environment variables. Update the system.config.yml to use secure cryptographic settings and disable deprecated encryption methods like crypto.createCipher. Ensure Redis datastore access is restricted and tokens are encrypted with AES-256-GCM.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart