PT-2026-30796 · Lollms · Lollms

CVE-2026-1114

·

Published

2026-01-07

·

Updated

2026-04-28

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions parisneo/lollms versions prior to 2.2.0
Description Session management is subject to improper access control because a weak secret key is used for signing JSON Web Tokens (JWT). This allows an attacker to conduct an offline brute-force attack to recover the secret key and subsequently forge administrative tokens by modifying the JWT payload. This process enables unauthorized users to escalate privileges, impersonate the administrator, and access restricted endpoints.
Recommendations Update to version 2.2.0.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06488
CVE-2026-1114
GHSA-9296-V3FR-J92J
PYSEC-2026-170

Affected Products

Lollms