Hoppscotch <= 2026.4.1 - Mass Assignment JWT_SECRET Overwrite
CVE-2026-50160
Verified
Description
Hoppscotch self-hosted backend <= 2026.4.1 contains a broken authentication caused by mass assignment via unauthenticated POST /v1/onboarding/config endpoint, letting unauthenticated attackers overwrite JWT_SECRET to forge tokens and fully compromise the server, exploit requires attacker to access fresh instance before onboarding completes or when no users exist.
Severity
Critical
CVSS Score
10
Exploit Probability
2%
Affected Product
hoppscotch
Published Date
August 8, 2026
Template Author
str4k3r
CVE-2026-50160.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVE ID:
cve-2026-50160
CWE ID:
cwe-915
Remediation Steps
Update to version 2026.5.0 or later.