LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-56265

kidocode · crawl4ai

Published
CVSS9.8
Severitycritical
WeaknessCWE-798
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-56265

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-56265.