PatchSiren cyber security CVE debrief
CVE-2026-108860 SciSharp CVE debrief
CVE-2026-108860 BotSharp Hard-Coded JWT Signing Key Authentication Bypass. The vulnerability allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json, enabling impersonation of any known user, including administrators, on Authorize-protected API routes. Defenders of BotSharp deployments, particularly those using version 5.2.0 or earlier, should assess exposure and prioritize remediation. The CVE record and source item provide details on the authentication bypass vulnerability.
- Vendor
- SciSharp
- Product
- BotSharp
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders of BotSharp deployments, particularly those using version 5.2.0 or earlier, should assess exposure and prioritize remediation. This includes operators, administrators, and security teams responsible for maintaining and securing BotSharp installations. They should review and update BotSharp to a version beyond 5.2.0 if available, implement additional authentication mechanisms, and monitor API routes for suspicious activity.
Why it matters
CVE-2026-108860 is a critical authentication bypass vulnerability in BotSharp through 5.2.0, allowing unauthenticated remote attackers to forge bearer tokens and impersonate users on protected API routes. Defenders of BotSharp deployments should assess exposure and prioritize remediation.
- Unauthenticated remote attackers can impersonate any known user, including administrators, on Authorize-protected API routes.
- Defenders must verify BotSharp version and configuration to determine exposure.
- Remediation priority is high due to the critical CVSS score of 9.3.
Technical summary
BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. This enables impersonation of any known user, including administrators, on Authorize-protected API routes. The vulnerability is due to the hard-coded Jwt:Key, which allows attackers to sign tokens with the committed HMAC secret and fixed botsharp issuer and audience. Defenders must verify BotSharp version and configuration to determine exposure and prioritize remediation.
Defensive priority
High
Recommended defensive actions
- Review and update BotSharp to a version beyond 5.2.0 if available
- Implement additional authentication mechanisms for API routes
- Monitor API routes for suspicious activity
- Restrict access to sensitive API routes
- Verify BotSharp version and configuration to determine exposure
- Conduct thorough vulnerability assessment and penetration testing to identify potential attack vectors
- Enhance incident response plans to address potential authentication bypass incidents
Evidence notes
The CVE record and source item provide details on the authentication bypass vulnerability in BotSharp through 5.2.0, which allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108860 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108860
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108860 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108860
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108860.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/scisharp-botsharp-public-jwt-signing-key
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/WebStarter/appsettings.json
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/SciSharp/BotSharp/blob/a11ee0317cab5c619df1cb5d0c4fc39d1b6e30b4/src/Infrastructure/BotSharp.OpenAPI/BotSharpOpenApiExtensions.cs
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/SciSharp/BotSharp
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/botsharp-through-5.2.0-authentication-bypass-via-hard-coded-jwt-signing-key
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.