CRITICAL
9.8 CVE-2026-85391 Published 3 Sept 2026
Peppermint JWT Signing Secret Exposure
Worried this affects one of your servers?
Peppermint, a web application, is affected by a hardcoded JWT signing secret in its docker-compose.yml file.
Attackers can exploit this to forge session tokens for any account, allowing them to access protected endpoints without valid credentials.
Reference: CVE-2026-85391 on NVD
← Back to Security News