Description
The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.
Published: 2026-09-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in yfexam‑exam version 2.0 results from deriving the JWT signing secret from the username and the current month instead of a random, server‑side key. This deterministic, low‑entropy secret enables an attacker who knows or can guess a username and the month to compute the secret by brute‑forcing potential values. With the secret in hand, the attacker can forge JSON Web Tokens that the application will accept, effectively allowing impersonation of any user account. The weakness is rooted in poor key generation and entropy, as reflected by the CWE reference CWE‑330.

Affected Systems

The affected product is yfexam‑exam version 2.0. No other vendors or version details are listed in the advisory.

Risk and Exploitability

The CVSS score of 7.5 places the vulnerability in the moderate‑to‑high severity range, while the EPSS score of less than 1% indicates a low probability of exploitation currently. The likely attack vector is remote HTTP endpoints that validate JWTs; the description indicates the attacker needs to know a username and month to derive the secret, and this is inferred because the advisory does not explicitly describe the method of attack. Exploitation would involve sending crafted tokens to the application, requiring no local privilege escalation. The vulnerability is not listed in the CISA KEV catalog, but its ability to forge tokens makes it a serious threat.

Generated by OpenCVE AI on September 10, 2026 at 07:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Generate a secure, random server‑side secret for signing JWTs and store it in a protected configuration store.
  • Rotate the signing key regularly and enforce short token lifetimes to limit the window for token replay.
  • Validate every incoming JWT against the current secret and reject tokens that fail verification.

Generated by OpenCVE AI on September 10, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title JWT Signing Secret Derived from Username and Month Exposes yfexam‑exam v2.0

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title JWT Signing Secret Derived from Username and Current Month Enables Brute‑Force Extraction
Weaknesses CWE-327
CWE-798

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-330
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title JWT Signing Secret Derived from Username and Current Month Enables Brute‑Force Extraction
Weaknesses CWE-327
CWE-798

Tue, 08 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T14:58:42.915Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79575

cve-icon Vulnrichment

Updated: 2026-09-09T14:58:32.679Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T15:18:48.300

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-79575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses
  • CWE-330

    Use of Insufficiently Random Values