CVE-2026-42869

CRITICAL

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value...

Affects 0 products across 3 vendors.

BCS6.68
CVSS 3.110.0
EPSS0.4%
Percentile36th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

CWE-522: CWE-522
CWE-798: Use of Hard-Coded Credentials

Software contains embedded passwords or keys that cannot be changed by the administrator.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-70 Try Common or Default Usernames and Passwords
via CWE-798
CAPEC-102 Session Sidejacking
via CWE-522
CAPEC-191 Read Sensitive Constants Within an Executable
via CWE-798
CAPEC-474 Signature Spoofing by Key Theft
via CWE-522
Show all 25

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

SOCFortress CoPilot versions prior to 0.1.57 contain a hardcoded JWT signing secret, which can be exploited to forge authentication tokens, leading to unauthorized access.

BSID: BS-2026-GLOBAL-152905-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-42869?
SOCFortress CoPilot versions prior to 0.1.57 contain a hardcoded JWT signing secret, which can be exploited to forge authentication tokens, leading to unauthorized access.
What is the CVSS score for CVE-2026-42869?
CVE-2026-42869 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-42869 actively exploited?
No confirmed active exploitation of CVE-2026-42869 as of 2026-05-30.
How do I remediate CVE-2026-42869?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-42869?
CVE-2026-42869 affects: Docker, Full, Verbatim.
Vulnerability Details
CVE IDCVE-2026-42869
BSIDBS-2026-GLOBAL-152905-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2026-05-11
Last Modified2026-05-13
ICS Relevance15%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrary admin-scoped JWTs and gain full control of the application and every security tool it manages without any credentials. This vulnerability is fixed in 0.1.57.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit the hardcoded JWT signing secret to generate valid authentication tokens, allowing them to impersonate legitimate users and gain unauthorized access to the system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Docker —
Full —
Verbatim —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 85 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf29b39cb83699ef3cc6af60cd8e1f88a15f91b3e03d3560d29ff2a9a2158fb23c2b96ed394417f1100f74b4ab61cd4517871b9baf5a09ade9624d561f1da666a
Related CVEs affecting Docker
CVE-2014-9357 10.0 Docker 1.3.2 allows remote attackers to execute arbitrary code with root priv... CVE-2024-29895 10.0 Cacti provides an operational monitoring and fault management framework. A co... CVE-2024-41110 9.9 Moby is an open-source project created by Docker for software containerizatio... CVE-2026-42454 9.9 Termix is a web-based server management platform with SSH terminal, tunneling... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th...
View all Docker CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →