CVE-2026-107177
Awaiting Analysis
Awaiting Analysis - Queue
Hardcoded Cryptographic Key in Express Gateway
Vulnerability report for CVE-2026-107177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: VulnCheck
Description
Description
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ExpressGateway | express-gateway | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1394 | The product uses a default cryptographic key for potentially critical functionality. |