PT-2026-66591 · Unknown · Outstatic Cms
CVE-2026-52539
·
Published
2026-07-30
·
Updated
2026-07-31
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Outstatic CMS versions prior to 2.2.0
Description
The application contains a hardcoded JSON Web Token (JWT) signing secret. If the
OST TOKEN SECRET environment variable is not configured, the system uses a default secret available in the public source code. This allows an unauthenticated remote attacker to forge JWT session tokens containing arbitrary user data, granting them full administrative permissions.Recommendations
Update Outstatic CMS to version 2.2.0 or later.
Set the
OST TOKEN SECRET environment variable to a unique, secure value.Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Outstatic Cms