logo

CVE-2026-49352: 9Router Hardcoded JWT Secret Allows Complete Authentication Bypass

ID: 0eff3815-1124-5d67-8cb3-fe132c1076bf

STIX ID: report--0eff3815-1124-5d67-8cb3-fe132c1076bf

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

**CVE-2026-49352 — 9Router (CVSS 9.8):** A hardcoded fallback JWT secret ('9router-default-secret-change-me') present in 9Router versions 0.2.21–0.4.43 enables attackers to sign tokens, set the auth_token cookie, bypass authentication and obtain administrative control; remediation is to upgrade to v0.4.44+, set and rotate a strong JWT_SECRET, invalidate sessions and audit logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.