Description
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Remote Access
Action: Patch immediately
AI Analysis

Impact

The flaw resides in the JWT Secret Handler of SciPhi-AI R2R and allows hard‑coded bcrypt and NaCl secret keys to be used by default. With knowledge of these constants an attacker can forge or decrypt JSON Web Tokens, thereby bypassing authentication and potentially accessing protected data. The vulnerability can be triggered remotely and the exploit has been publicly disclosed.

Affected Systems

SciPhi‑AI R2R installations up to version 3.6.6 are affected. No information is provided about patches, so any deployment running these versions remains vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS data are not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote network access, and the public disclosure suggests that exploitation is likely possible without additional setup.

Generated by OpenCVE AI on October 4, 2026 at 13:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SciPhi‑AI R2R to a version where the hard‑coded JWT secret keys have been removed or apply any vendor release that addresses the issue.
  • If an upgrade is not immediately feasible, configure the application to inject a unique JWT secret key, overriding the default constants.
  • Restrict external network reach to the R2R service through firewalls or network segmentation to reduce the attack surface.
  • Monitor authentication and token‑generation logs for abnormal activity that could indicate credential misuse.

Generated by OpenCVE AI on October 4, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title SciPhi-AI R2R JWT Secret hard-coded credentials
First Time appeared Sciphi-ai
Sciphi-ai r2r
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:sciphi-ai:r2r:*:*:*:*:*:*:*:*
Vendors & Products Sciphi-ai
Sciphi-ai r2r
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T11:15:12.371Z

Reserved: 2026-10-03T18:05:09.991Z

Link: CVE-2026-105147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T13:16:54.773

Modified: 2026-10-04T13:16:55.630

Link: CVE-2026-105147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T14:00:14Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials