https://seclists.org/oss-sec/2026/q2/1007: [CVE-2026-50160] Hoppscotch: Unauthenticated JWT Sect Overwrite (CVSS 10.0)
Published Jun 23, 2026
·Updated
Affected Software
1 affected component
hoppscotch Hoppscotch (self-hosted)<=2026.4.1
Frequently Asked Questions
1
What is CVE-2026-50160?
CVE-2026-50160 is a critical vulnerability in Hoppscotch that allows unauthenticated overwriting of JWT secrets.
2
What is the severity of CVE-2026-50160?
CVE-2026-50160 has a CVSS score of 10.0, indicating it is a critical vulnerability.
3
How do I fix CVE-2026-50160?
To fix CVE-2026-50160, ensure that your Hoppscotch installation is updated to the latest version that addresses this vulnerability.
4
Who is affected by CVE-2026-50160?
CVE-2026-50160 affects users of the self-hosted version of Hoppscotch.
5
When was CVE-2026-50160 published?
CVE-2026-50160 was published on June 23, 2026.