CVE-2026-1114Disclosure(lollms / lollms)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch lollms lollms systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the secret key is obtained, the attacker can forge administrative tokens by modifying the JWT payload and resigning it with the cracked secret. This enables unauthorized users to escalate privileges, impersonate the administrator, and gain access to restricted endpoints. The issue is resolved in version 2.2.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lollms

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-07); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
lollms

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-07: 4Mentions · 2026-04-19: 2PoC Mentioned / Linked · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 4Technical Details · 2026-04-19: 204-0704-19
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-074
Disclosure3Patch1
2026-04-192
Disclosure2
Full discourse6 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1114: Improper... Weak JWT secrets = admin access via offline bruteforce - LOLLMS basically handed attackers the keys to forge admin tokens at scale #JWT #PrivEsc. https://zerodaysignal.com/vulnerability/CVE-2026-1114 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑1114, detailing how weak JWT secrets can lead to admin access via offline brute‑force, but does not provide a working exploit or evidence of active attacks.

    1000046
    204 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1114 In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web… https://www.cve.org/CVERecord?id=CVE-2026-1114 ----- Traducción: CVE-2026-1114 En … http://infoflow.cloud`

    Post summary

    The tweet announces a new CVE (CVE‑2026‑1114) describing a session‑management vulnerability caused by a weak JWT signing key.

    0000037
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1114 In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web… https://www.cve.org/CVERecord?id=CVE-2026-1114

    Post summary

    The announcement details a session management flaw in parisneo/lollms 2.1.0 caused by a weak secret key used for signing JSON Web tokens, leading to improper access control.

    00000203
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1114 Weak JWT Secret Key Enables Privilege Escalation in parisneo/lollms 2.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1114

    Post summary

    CVE-2026-1114 reveals that a weak JWT secret key in parisneo/lollms 2.1.0 permits privilege escalation. The post serves as a vulnerability disclosure without mention of PoC, exploits, or patches.

    0000045
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1114 - Improper Access Control via Weak JWT Token in parisneo/lollms Intel Report: https://ift.tt/jU4J1wK

    Post summary

    Alert announces CVE-2026-1114, noting an improper access control flaw caused by weak JWT tokens in parisneo/lollms, with a link to an Intel report but no PoC, exploit, patch, or active exploitation details.

    0000029
    281 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1114: CRITICAL] Vulnerability in Parisneo/lollms 2.1.0! Weak secret key in JWT allows unauthorized access. Update to version 2.2.0 to fix this cyber security flaw. #cybersecurity#cve,CVE-2026-1114,#cybersecurity https://cvefind.com/CVE-2026-1114

    Post summary

    The post announces CVE-2026-1114, highlighting a critical weakness in the JWT secret key of Parisneo/lollms 2.1.0, and recommends updating to version 2.2.0, providing basic technical details but no proof of exploitation.

    0000037
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applollmslollms2.1.0--

Explore more