Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials. | |
| Title | Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml | |
| First Time appeared |
Peppermint
Peppermint peppermint |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:peppermint:peppermint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Peppermint
Peppermint peppermint |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T19:00:50.811Z
Reserved: 2026-09-03T18:10:51.946Z
Link: CVE-2026-85391
Updated: 2026-09-03T19:00:44.932Z
Status : Received
Published: 2026-09-03T19:17:30.830
Modified: 2026-09-03T20:17:28.467
Link: CVE-2026-85391
No data.
OpenCVE Enrichment
No data.
-
CWE-798
Use of Hard-coded Credentials