Critical severity9.1NVD Advisory· Published Oct 11, 2026
CVE-2026-108860
CVE-2026-108860
Description
BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. Attackers can sign tokens with the committed HMAC secret and fixed botsharp issuer and audience to impersonate any known user, including administrators, on Authorize-protected API routes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/Infrastructure/BotSharp.OpenAPI/BotSharpOpenApiExtensions.csnvd
- github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/WebStarter/appsettings.jsonnvd
- hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/scisharp-botsharp-public-jwt-signing-keynvd
- www.vulncheck.com/advisories/botsharp-through-5.2.0-authentication-bypass-via-hard-coded-jwt-signing-keynvd
News mentions
0No linked articles in our index yet.