Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.

Project Subscriptions

Vendors Products
Peppermint Subscribe
Peppermint Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.
Title Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml
First Time appeared Peppermint
Peppermint peppermint
Weaknesses CWE-798
CPEs cpe:2.3:a:peppermint:peppermint:*:*:*:*:*:*:*:*
Vendors & Products Peppermint
Peppermint peppermint
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T19:00:50.811Z

Reserved: 2026-09-03T18:10:51.946Z

Link: CVE-2026-85391

cve-icon Vulnrichment

Updated: 2026-09-03T19:00:44.932Z

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:30.830

Modified: 2026-09-03T20:17:28.467

Link: CVE-2026-85391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses