CRITICAL 9.8 CVE-2026-85391 Published 3 Sept 2026

Peppermint JWT Signing Secret Exposure

Worried this affects one of your servers?

Peppermint, a web application, is affected by a hardcoded JWT signing secret in its docker-compose.yml file.

Attackers can exploit this to forge session tokens for any account, allowing them to access protected endpoints without valid credentials.

Reference: CVE-2026-85391 on NVD

← Back to Security News