CVE-2026-107177: Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens

Published Oct 7, 2026
·
Updated

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.

Affected Software

1 affected component
Express Gateway Express Gateway<=1.16.11

Event History

Oct 7, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Deployments of Express Gateway through 1.16.11 that use the default crypto.cipherKey value and store OAuth 2.0 token data in Redis are exposed. An attacker must be able to read the Redis datastore.

2

What does an attacker need to exploit the vulnerability?

The attacker needs access to read Redis values containing tokenEncrypted data and the associated stored token IDs. They can use the hardcoded default cipherKey, sensitiveKey, to decrypt the token secrets and obtain valid bearer tokens.

3

Are affected systems vulnerable through the network without prior access?

No direct unauthenticated network-only attack is described. Exploitation requires high privileges and datastore read access, and the attack complexity is rated high.

4

How can I determine whether my deployment is affected?

Check whether the Express Gateway version is 1.16.11 or earlier and whether crypto.cipherKey remains set to the default value, sensitiveKey. Also determine whether OAuth token secrets are stored in Redis as tokenEncrypted values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203