CRITICAL
SciSharp
CVE published 2026-10-11
CVE-2026-108860
CVE-2026-108860 BotSharp Hard-Coded JWT Signing Key Authentication Bypass. The vulnerability allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json, enabling impersonation of any known user, including administrators, on Authorize-protected API routes. Defenders of BotSharp deployments, particularly those using version 5.2.0 or earlier, sh [truncated]