Sceawere
Vulnerability Detail
CVE-2026-108860UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
BotSharp Hard-Coded JWT Secret Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 3h ago
- Vendor
- SciSharp
- Product
- BotSharp
- Attack Type
- Use of Hard-coded Cryptographic Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. Attackers can sign tokens with the committed HMAC secret and fixed botsharp issuer and audience to impersonate any known user, including administrators, on Authorize-protected API routes.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-11T14:17:05.933Z",
"pubdate": "2026-10-11T14:17:05.933Z",
"executiveSummary": "BotSharp versions up to and including 5.2.0 are susceptible to a critical authentication bypass vulnerability due to the inclusion of a hard-coded cryptographic key within the source code.\nSpecifically, the WebStarter application utilizes a static, publicly accessible value for the 'Jwt:Key' defined in the 'appsettings.json' configuration file.\nThis flaw allows unauthenticated remote attackers to perform unauthorized cryptographic operations, specifically the generation of valid, signed JSON Web Tokens (JWT).\nBy leveraging this known secret, an adversary can forge tokens for any arbitrary user account within the system, including administrative accounts, effectively bypassing all Authorize-protected API routes.\nThe risk is categorized as critical because the vulnerability does not require prior authentication or specialized access to the underlying server infrastructure, only network reachability to the application's authentication endpoints.\nThe impact includes full administrative impersonation, unauthorized access to sensitive bot configurations, conversation data, and system-level administrative functions, leading to complete compromise of the BotSharp instance.",
"technicalDetails": "The vulnerability resides within the JWT authentication middleware implementation of the WebStarter component in BotSharp 5.2.0 and earlier. The application utilizes an insecure, hard-coded string as the symmetric HMAC signing key for JWT generation and validation, stored in plain text within the 'appsettings.json' configuration file.\nJSON Web Tokens (JWT) rely on a secret key to ensure the integrity and authenticity of the claims contained within the token. By embedding this secret in the source code or configuration files, the developers have inadvertently exposed the root of trust for the entire authentication system.\nAn attacker can exploit this by obtaining the hard-coded key from the public repository or the distributed application package. Once the key is obtained, the attacker can construct a malicious JWT payload. The structure of the forged token requires three components: the header, the payload, and the signature.\nThe attacker sets the 'alg' field in the header to 'HS256' (the expected algorithm for HMAC). In the payload, the attacker populates the 'sub' (subject), 'iss' (issuer), and 'aud' (audience) claims using the fixed values hard-coded within the BotSharp framework. The attacker can then specify any user ID or administrative role within the claims.\nUsing the hard-coded secret, the attacker calculates the HMAC SHA-256 signature for the header and payload. Because the server uses the same hard-coded secret to validate incoming tokens, the application's middleware will accept the attacker-generated token as legitimate.\nThe attack flow is as follows: 1. The attacker retrieves the hard-coded 'Jwt:Key' from the application configuration. 2. The attacker identifies the application's specific 'issuer' and 'audience' configuration values. 3. The attacker crafts a JWT with elevated administrative claims. 4. The attacker signs the JWT using the obtained key. 5. The attacker submits the forged token in the Authorization header (Bearer scheme) to any endpoint protected by the Authorize attribute. 6. The application validates the signature successfully, granting the attacker full administrative access to the API.\nThis vulnerability bypasses all session management and access control checks, allowing an unauthenticated attacker to impersonate any user, delete bots, access sensitive historical interaction logs, or modify system configurations without any server-side validation of the token's origin."
}