All 4 CVE vulnerabilities found in MaxKey, with AI-generated Chinese analysis, references, and POCs.
Vendor: Dromara
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-69102 | MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust CWE-798 | 9.8 | Critical | 2026-08-11 |
| CVE-2026-67345 | MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft CWE-183 | 8.1 | High | 2026-07-30 |
| CVE-2026-7699 | Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection CWE-89 | 6.3 | Medium | 2026-05-03 |
| CVE-2025-6517 | Dromara MaxKey Meta URL SAML20DetailsController.java add server-side request forgery CWE-918 | 6.3 | Medium | 2025-06-23 |
All 4 known CVE vulnerabilities affecting MaxKey with full Chinese analysis, references, and POCs where available.