CVE-2026-42869Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly set — including the default Docker Compose setup — signs all authentication tokens with this publicly known value. An unauthenticated attacker can forge arbitrary admin-scoped JWTs and gain full control of the application and every security tool it manages without any credentials. This vulnerability is fixed in 0.1.57.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-522CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-23)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-12: 1Mentions · 2026-06-23: 2Technical Details · 2026-05-12: 1Technical Details · 2026-06-23: 205-1206-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-06-232
Disclosure2
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    SOCFortress CoPilot CVSS 10: Hardcoded JWT Secret Grants Unauthenticated Full Admin On May 11, 2026, security researchers disclosed CVE-2026-42869, a perfect-storm authentication bypass in SOCFortress CoPilot—a single-pane-of-glass security operations platform used to…

    Post summary

    Security researchers disclosed CVE-2026-42869, an authentication bypass in SOCFortress CoPilot caused by a hardcoded JWT secret granting unauthenticated full admin rights, with no mention of PoC, exploitation, or patch.

    1000038
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42869 · 0.1.57 SOCFortress CoPilot CVSS 10: Hardcoded JWT Secret Grants Unauthenticated Full Admin

    Post summary

    The note announces CVE-2026-42869 for SOCFortress CoPilot V0.1.57, describing a CVSS 10 vulnerability where a hardcoded JWT secret allows unauthenticated users to gain full admin privileges.

    1000043
    295 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-42869 (SOCFortress CoPilot) is a critical authentication bypass via hardcoded JWT secret fallback. High Risk See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-11/TIER_2_CVE-2026-42869.md #CyberSecurity #DPI #SOC #CloudSecurity #VulnerabilityManagement

    Post summary

    The text announces CVE-2026-42869 as a critical authentication bypass via hardcoded JWT secret fallback, providing technical details but no PoC, exploit, or patch information.

    0000052
    43 followersView on X

Explore more