/Vulnerability Library

Hoppscotch <= 2026.4.1 - Mass Assignment JWT_SECRET Overwrite

CVE-2026-50160
Verified

Description

Hoppscotch self-hosted backend <= 2026.4.1 contains a broken authentication caused by mass assignment via unauthenticated POST /v1/onboarding/config endpoint, letting unauthenticated attackers overwrite JWT_SECRET to forge tokens and fully compromise the server, exploit requires attacker to access fresh instance before onboarding completes or when no users exist.

Severity

Critical

CVSS Score

10

Exploit Probability

2%

Affected Product

hoppscotch

Published Date

August 8, 2026

Template Author

str4k3r

CVE-2026-50160.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVE ID:
cve-2026-50160
CWE ID:
cwe-915

References

https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-j542-4rch-8hwfhttps://nvd.nist.gov/vuln/detail/CVE-2026-50160https://github.com/hoppscotch/hoppscotch/pull/6171

Remediation Steps

Update to version 2026.5.0 or later.