Back to overview

CVE-2026-1114

CRITICAL Exploitation: PoC
9.8
CVSS 3.0
Description
In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the secret key is obtained, the attacker can forge administrative tokens by modifying the JWT payload and resigning it with the cracked secret. This enables unauthorized users to escalate privileges, impersonate the administrator, and gain access to restricted endpoints. The issue is resolved in version 2.2.0.

Metadata

CVE ID
CVE-2026-1114
State
PUBLISHED
Assigner
@huntr_ai
Reserved
2026-01-17 13:03 UTC
Published
2026-04-07 06:19 UTC
Last updated
2026-04-07 13:20 UTC
Primary CWE
CWE-284
CWE-284 Improper Access Control
Vendor / Product
parisneo / parisneo/lollms
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
parisneo parisneo/lollms unspecified < 2.2.0
Weakness (CWE)
CWESourceDescription
CWE-284 cna CWE-284 Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview