CVE-2026-42869
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value...
Affects 0 products across 3 vendors.
Software does not prove or insufficiently proves that the user is who they claim to be.
Software contains embedded passwords or keys that cannot be changed by the administrator.
Show all 25
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
SOCFortress CoPilot versions prior to 0.1.57 contain a hardcoded JWT signing secret, which can be exploited to forge authentication tokens, leading to unauthorized access.
BSID: BS-2026-GLOBAL-152905-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-42869?
What is the CVSS score for CVE-2026-42869?
Is CVE-2026-42869 actively exploited?
How do I remediate CVE-2026-42869?
What systems are affected by CVE-2026-42869?
| CVE ID | CVE-2026-42869 |
|---|---|
| BSID | BS-2026-GLOBAL-152905-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-05-11 |
| Last Modified | 2026-05-13 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrary admin-scoped JWTs and gain full control of the application and every security tool it manages without any credentials. This vulnerability is fixed in 0.1.57.
Source: NIST NVD / MITRE CVE Database
An attacker can exploit the hardcoded JWT signing secret to generate valid authentication tokens, allowing them to impersonate legitimate users and gain unauthorized access to the system.
Exploitation Likelihood: CRITICAL
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | f29b39cb83699ef3cc6af60cd8e1f88a15f91b3e03d3560d29ff2a9a2158fb23c2b96ed394417f1100f74b4ab61cd4517871b9baf5a09ade9624d561f1da666a |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →