External risk intelligence

BotSharp Authentication Bypass Via Hardcoded JWT Key

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-108860

BotSharp is a framework designed for building conversational AI agents and APIs. Because it exposes Web API endpoints for integration and interaction, it is commonly deployed as a web-accessible service. The vulnerability affects these API routes, which are intended to be reachable, making internet-facing exposure a likely deployment pattern for this product.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE describes a vulnerability in BotSharp, a platform for building AI chatbots, that allows unauthorized access to protected API routes. An attacker can forge authentication tokens to impersonate users, including administrators, within the application. The primary concern at this time is to confirm if this technology is in use and exposed.

  • Bypass of user authentication in BotSharp.
  • Attackers can impersonate any user, including admins.
  • Confirm if BotSharp is used and exposed.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests to the WebStarter application. Since the JWT signing key is hardcoded and predictable, an attacker can forge a valid bearer token. This forged token can then be used to impersonate any user, including administrators, to access protected API routes without legitimate authentication. The ultimate goal is to gain unauthorized access to sensitive data or functionality within the application.

  • No authentication or network access required.
  • Forging bearer tokens using hardcoded keys.
  • Unauthorized access to administrative functions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated remote attackers to impersonate any user, including administrators, on protected API routes by forging bearer tokens. This is possible when the hard-coded JWT signing key in the application's configuration is used.

  • API routes and user sessions.
  • Forging bearer tokens with hard-coded key.
  • Unauthorized access to sensitive information or actions.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary responsibility for addressing this authentication bypass vulnerability likely falls to the application owners or platform teams managing BotSharp deployments. The initial practical step involves identifying all instances of BotSharp, confirming their reachability and business criticality, and then establishing clear ownership for remediation. Following this, a risk-based plan for addressing the hard-coded JWT signing key should be developed, potentially involving vendor coordination or temporary mitigation strategies if immediate patching is not feasible.

  • Application owners should own the remediation.
  • Verify reachability and business criticality.
  • Plan secure key management and updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is BotSharp and why is it used?

BotSharp is an open-source framework designed for building and managing conversational AI agents and intelligent chatbot applications. Developers use it to create interactive API-driven services that handle natural language processing tasks. Because it serves as a platform for AI-powered agents, it is frequently integrated into web services that require persistent, authorized communication between users and the underlying bot infrastructure.

How does CVE-2026-108860 allow authentication bypass?

This vulnerability stems from the use of a hard-coded cryptographic key, classified as CWE-321. Because the JWT (JSON Web Token) signing key is fixed within the application's configuration, an attacker can mathematically reproduce it. By knowing this secret key, unauthorized parties can generate and sign their own valid tokens, effectively tricking the system into treating them as legitimate, authenticated users or even administrators.

Do I need special network access to trigger this bug?

No. The vulnerability does not require the attacker to have prior network access or existing credentials. Because the flaw relies on a predictable key used to sign tokens, an attacker only needs to be able to reach the application's API endpoints. If the API is reachable, an attacker can submit a forged token at any time to bypass the standard login process.

Is my BotSharp deployment at risk?

According to Halo Surface Signal, this software is commonly deployed as an internet-facing service to support conversational AI integrations. If your BotSharp instance is reachable from the public internet, it faces a higher likelihood of being targeted. You should assess whether your specific API endpoints are exposed to the open web or restricted to internal users.

What steps should I take if I run BotSharp?

First, inventory your systems to identify all instances of BotSharp across your environment. Once identified, verify which instances are internet-facing versus internal to determine priority. Coordinate with your engineering teams to establish ownership of the deployment, then focus on secure key management practices to replace the hard-coded secret. Monitor your infrastructure while planning a transition to a secure authentication configuration.

References