CVE-2026-107177

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,4
Attack Vector: network
Attack Complexity: high
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,9
Attack Vector: network
Attack Complexity: high
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.

1394

Use of Default Cryptographic Key

Incomplete
Common Consequences
Security Scopes Affected:
Authentication
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/ExpressGateway/express-gateway
https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf8…
https://github.com/ExpressGateway/express-gateway/blob/45612814d12f65889ef3bdf8…
https://github.com/ExpressGateway/express-gateway/issues/1078
https://www.vulncheck.com/advisories/express-gateway-through-1.16.11-hardcoded-…