CVE-2026-107177: Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Deployments of Express Gateway through 1.16.11 that use the default crypto.cipherKey value and store OAuth 2.0 token data in Redis are exposed. An attacker must be able to read the Redis datastore.
What does an attacker need to exploit the vulnerability?
The attacker needs access to read Redis values containing tokenEncrypted data and the associated stored token IDs. They can use the hardcoded default cipherKey, sensitiveKey, to decrypt the token secrets and obtain valid bearer tokens.
Are affected systems vulnerable through the network without prior access?
No direct unauthenticated network-only attack is described. Exploitation requires high privileges and datastore read access, and the attack complexity is rated high.
How can I determine whether my deployment is affected?
Check whether the Express Gateway version is 1.16.11 or earlier and whether crypto.cipherKey remains set to the default value, sensitiveKey. Also determine whether OAuth token secrets are stored in Redis as tokenEncrypted values.