Skip to content
CVE-2026-105392: Vulnerability in Lybbn Django-Vue-Lyadmin Exposes JWT Signing Key

CVE-2026-105392: Vulnerability in Lybbn Django-Vue-Lyadmin Exposes JWT Signing Key

First seen 6 Oct 2026, 01:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 02:26 UTC
  • •CVE-2026-105392 allows unauthenticated remote exploitation via a hard-coded SECRET_KEY.
  • •Affected versions include Lybbn Django-Vue-Lyadmin up to 3.2.12.
  • •Developers must replace the default SECRET_KEY to mitigate risks of token forgery.

A vulnerability identified as CVE-2026-105392 affects Lybbn Django-Vue-Lyadmin versions up to 3.2.12. The flaw arises from a hard-coded SECRET_KEY in backend/application/settings.py, allowing unauthenticated remote exploitation. Attackers can forge JWT tokens, potentially bypassing authentication and impersonating users. The vulnerability has been disclosed publicly, with proof-of-concept code available. Publicly reachable deployments and instances using default settings are at the highest risk. Developers are advised to change the SECRET_KEY before deployment, but many may not have done so. The CVSS score for this vulnerability is 6.9, categorized as medium severity. No fixed release has been identified yet, and mitigation steps include replacing the signing secret and restricting access to administrative functions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
CVE-2026-105392 published
The vulnerability was disclosed, highlighting the risk of unauthenticated remote exploitation through a hard-coded SECRET_KEY.
Redpacketsecurity
2026-10-06
Public proof-of-concept confirmed
A proof-of-concept for exploiting the vulnerability was confirmed against a default local deployment, demonstrating the risk of token forgery.
github.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-105392 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Lybbn Django-Vue-Lyadmin versions up to 3.2.12 are affected by this vulnerability.
Is there a patch available?
No fixed release has been identified yet, so users should implement mitigation measures immediately.
What should I do to secure my deployment?
Replace the hard-coded SECRET_KEY with a unique, high-entropy value and restrict access to administrative functions.