CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52539

criticalCVSS 9.1covered by 1 sourcefirst seen 2026-07-30
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

⚡ Watch CVE-2026-52539

Get an email if CVE-2026-52539 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-52539

CVE.org record

Embed the live status

CVE-2026-52539 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52539 status](https://www.csirts.com/badge/CVE-2026-52539)](https://www.csirts.com/cve/CVE-2026-52539)