CRITICALVulnerability

CVE-2026-85391

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-85391
signal_observed_at
2026-09-15T21:20:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-09-03T19:17:30.830
last_modified
2026-09-09T20:20:21.673

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Credentials

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85391 — Ninja Signal Threat Intelligence | Ninja Signal