PT-2026-66591 · Unknown · Outstatic Cms

CVE-2026-52539

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Outstatic CMS versions prior to 2.2.0
Description The application contains a hardcoded JSON Web Token (JWT) signing secret. If the OST TOKEN SECRET environment variable is not configured, the system uses a default secret available in the public source code. This allows an unauthenticated remote attacker to forge JWT session tokens containing arbitrary user data, granting them full administrative permissions.
Recommendations Update Outstatic CMS to version 2.2.0 or later. Set the OST TOKEN SECRET environment variable to a unique, secure value.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52539

Affected Products

Outstatic Cms