CVE-2026-82827: A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions.
This issue affects Hitachi Coding Software Suite: through 3.3.0.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Hitachi Coding Software Suite versions through 3.3.0 are affected.
What does an attacker need to exploit this issue?
An attacker can generate fraudulent Bearer tokens using the hard-coded JWT signing secret key. The provided data indicates no authentication, user interaction, or special privileges are required.
What access could a successful attacker obtain?
A successful attacker can use unauthorized Bearer tokens to abuse administrative functions. The vulnerability is rated critical with impacts to confidentiality, integrity, and availability.