PT-2026-30796 · Lollms · Lollms
Published
2026-01-07
·
Updated
2026-04-28
·
CVE-2026-1114
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms versions prior to 2.2.0
Description
Session management is subject to improper access control because a weak secret key is used for signing JSON Web Tokens (JWT). This allows an attacker to conduct an offline brute-force attack to recover the secret key and subsequently forge administrative tokens by modifying the JWT payload. This process enables unauthorized users to escalate privileges, impersonate the administrator, and access restricted endpoints.
Recommendations
Update to version 2.2.0.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms