PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108860 SciSharp CVE debrief

CVE-2026-108860 BotSharp Hard-Coded JWT Signing Key Authentication Bypass. The vulnerability allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json, enabling impersonation of any known user, including administrators, on Authorize-protected API routes. Defenders of BotSharp deployments, particularly those using version 5.2.0 or earlier, should assess exposure and prioritize remediation. The CVE record and source item provide details on the authentication bypass vulnerability.

Vendor
SciSharp
Product
BotSharp
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders of BotSharp deployments, particularly those using version 5.2.0 or earlier, should assess exposure and prioritize remediation. This includes operators, administrators, and security teams responsible for maintaining and securing BotSharp installations. They should review and update BotSharp to a version beyond 5.2.0 if available, implement additional authentication mechanisms, and monitor API routes for suspicious activity.

Why it matters

CVE-2026-108860 is a critical authentication bypass vulnerability in BotSharp through 5.2.0, allowing unauthenticated remote attackers to forge bearer tokens and impersonate users on protected API routes. Defenders of BotSharp deployments should assess exposure and prioritize remediation.

  • Unauthenticated remote attackers can impersonate any known user, including administrators, on Authorize-protected API routes.
  • Defenders must verify BotSharp version and configuration to determine exposure.
  • Remediation priority is high due to the critical CVSS score of 9.3.

Technical summary

BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. This enables impersonation of any known user, including administrators, on Authorize-protected API routes. The vulnerability is due to the hard-coded Jwt:Key, which allows attackers to sign tokens with the committed HMAC secret and fixed botsharp issuer and audience. Defenders must verify BotSharp version and configuration to determine exposure and prioritize remediation.

Defensive priority

High

Recommended defensive actions

  • Review and update BotSharp to a version beyond 5.2.0 if available
  • Implement additional authentication mechanisms for API routes
  • Monitor API routes for suspicious activity
  • Restrict access to sensitive API routes
  • Verify BotSharp version and configuration to determine exposure
  • Conduct thorough vulnerability assessment and penetration testing to identify potential attack vectors
  • Enhance incident response plans to address potential authentication bypass incidents

Evidence notes

The CVE record and source item provide details on the authentication bypass vulnerability in BotSharp through 5.2.0, which allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108860 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108860

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108860 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108860

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108860.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/scisharp-botsharp-public-jwt-signing-key

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/WebStarter/appsettings.json

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/Infrastructure/BotSharp.OpenAPI/BotSharpOpenApiExtensions.cs

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/SciSharp/BotSharp

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/botsharp-through-5.2.0-authentication-bypass-via-hard-coded-jwt-signing-key

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.