What is CVE-2026-52539?
CVE-2026-52539 is a critical vulnerability in Outstatic CMS versions 2.1.9 and earlier, involving a hardcoded JWT signing secret. If the OST_TOKEN_SECRET environment variable is not set, the application falls back to a default value visible in the public source code repository, allowing an unauthenticated remote attacker to forge JWT sessions. Affected systems should immediately update the token secret and configure the environment variable.
Azərbaycanca: CVE-2026-52539, Outstatic CMS-in 2.1.9 və daha əvvəlki versiyalarında sərt kodlaşdırılmış JWT imzalama sirrinin istifadəsi ilə bağlı kritik qüsurdur. OST_TOKEN_SECRET mühit dəyişəni təyin edilmədikdə, tətbiq açıq mənbəli repoda görünən standart sirrə müraciət edir və bu, uzaqdan autentifikasiya olunmamış hücumçuya JWT sessiyalarını saxtalaşdırmağa imkan verir. Təsirə məruz qalan sistemlərdə dərhal token sirrini yeniləmək və mühit dəyişənini konfiqurasiya etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of Outstatic CMS are affected by CVE-2026-52539?
Outstatic CMS versions 2.1.9 and earlier are affected by this vulnerability.
What happens if the OST_TOKEN_SECRET environment variable is not set?
The application falls back to a default JWT signing secret visible in the public source code repository, allowing an unauthenticated remote attacker to forge JWT sessions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.