Summary
CVE-2026-69102 is a critical authentication bypass vulnerability in Dromara MaxKey, an open-source identity and access management/SSO platform. The flaw stems from a hard-coded JWT signing secret shipped in the application’s default configuration, allowing an unauthenticated remote attacker to forge trusted authentication tokens and obtain a fully authenticated administrative session. The issue carries a CVSS v4.0 base score of 9.3 (Critical) and a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: MaxKey ships with a static, publicly-known JWT signing secret hard-coded in
application-maxkey.properties. This secret is used to validate tokens submitted to the/sign/login/jwt/trustendpoint. - Trigger conditions: Any MaxKey deployment that has not overridden the default secret is exploitable. The trust-login flow (
HttpJwtEntryPoint.java/AuthJwtService.java/TrustedAuthenticationProvider.java) verifies only the JWT signature and thesub(subject) claim, without validating issuer/audience claims or requiring a password. - Attack vector: Network-based, no authentication or user interaction required. An attacker crafts a JWT (e.g., with
"sub":"admin") signed with the known default secret and submits it to the trust-login endpoint. - Impact: Successful exploitation grants the attacker a fully authenticated, admin-level session, exposing SSO application configurations and downstream federated application credentials/secrets — a complete compromise of confidentiality, integrity, and availability for the affected instance and any connected relying applications.
- Weakness class: CWE-798 (Use of Hard-coded Credentials).
Affected software
- Dromara MaxKey versions 0 through 4.1.11 (inclusive) — i.e., all releases up to and including 4.1.11 that use the default/unmodified JWT trust secret.
Severity
- CVSS v3.1 Base Score: 9.8 (Critical) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0 Base Score: 9.3 (Critical) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade to a MaxKey version that incorporates the fix delivered in commit
6cda394ec111f03a06fb2eed0de74f787d68bd97, which removes the shipped default JWT trust secret. - If unable to patch immediately:
- Rotate/replace the default JWT signing secret in
application-maxkey.propertieswith a strong, randomly generated, per-instance value. - Restrict or disable the
/sign/login/jwt/trustendpoint if the JWT trust-login feature is not required. - Enforce validation of issuer (
iss) and audience (aud) claims in addition to signature checks where custom configuration allows it. - Monitor authentication logs for unexpected admin sessions originating from the trust-login endpoint and audit SSO application configurations for unauthorized changes.
- Restrict network exposure of the MaxKey management/authentication endpoints to trusted networks where possible.
- Rotate/replace the default JWT signing secret in

