CVE-2026-79575 PUBLISHED

Assigner: mitre
Reserved: 25.08.2026 Published: 08.09.2026 Updated: 08.09.2026

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text