egOS WebGUI Hard-Coded JWT Secret Key Vulnerability Allowing Authentication Bypass

Vulnerability

A vulnerability exists in the egOS WebGUI backend where the JWT secret key is hard-coded and accessible to the default user. This allows an unauthenticated remote attacker to generate valid HS256 tokens, bypassing authentication and authorization mechanisms.

Impact

Exploitation of this vulnerability allows for authentication and authorization bypass, enabling unauthorized access to resources or functionalities that require user authentication.

Added: Aug 26, 2025, 6:21 AM
Updated: Aug 26, 2025, 6:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.