CVE-2026-79575: Yfexam-exam vulnerability
Published Sep 8, 2026
·Updated
The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.
Affected Software
1 affected component
yfexam-exam=2.0
Event History
Sep 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:18 PM
Description
Frequently Asked Questions
1
What information does an attacker need to derive the JWT signing secret?
The secret is derived from a username and the current month. An attacker can attempt to obtain it through brute force using those predictable inputs.
2
Which installations are identified as affected?
The provided information identifies yfexam-exam version 2.0 as affected.