A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.
References
Configurations
No configuration.
History
09 Feb 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 05:16
Updated : 2026-02-09 16:08
NVD link : CVE-2026-2215
Mitre link : CVE-2026-2215
CVE.ORG link : CVE-2026-2215
JSON object : View
Products Affected
No product.
CWE
CWE-1394
Use of Default Cryptographic Key
