CVE-2026-108860
Received Received - Intake

Authentication Bypass in BotSharp via Hard-Coded JWT Key

Vulnerability report for CVE-2026-108860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. Attackers can sign tokens with the committed HMAC secret and fixed botsharp issuer and audience to impersonate any known user, including administrators, on Authorize-protected API routes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SciSharp BotSharp 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BotSharp through version 5.2.0 has an authentication bypass flaw. Unauthenticated remote attackers can forge bearer tokens using a hard-coded JWT key found in the WebStarter appsettings.json file. The key allows signing tokens with a fixed HMAC secret and predefined issuer and audience values to impersonate any user, including administrators, on API routes protected by authorization checks.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized API access or unusual authentication patterns. Inspect logs for requests using bearer tokens signed with the hard-coded Jwt:Key. Look for tokens with the fixed issuer and audience values mentioned in the vulnerability description.

Impact Analysis

This vulnerability allows attackers to gain unauthorized access to sensitive API endpoints by impersonating legitimate users, including administrators. They could steal data, perform unauthorized actions, or escalate privileges within the application. The impact includes potential data breaches, system compromise, and loss of control over the application.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to personal or sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach could result in legal penalties, fines, and reputational damage due to failure to meet regulatory requirements.

Mitigation Strategies
  • Update BotSharp to a version that removes the hard-coded Jwt:Key and implements proper authentication.
  • Rotate the Jwt:Key secret in WebStarter appsettings.json if an update is not immediately available.
  • Audit all bearer tokens in use and invalidate any tokens that may have been forged using the hard-coded key.
  • Monitor API access logs for suspicious activity, such as unauthorized access attempts or impersonation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart