A critical vulnerability tracked as CVE-2026-49352 was disclosed in decolua's 9Router, where versions 0.2.21 through 0.4.43 used a hardcoded fallback JWT signing secret when JWT_SECRET was unset. An attacker could exploit the static secret to forge an auth_token cookie and bypass authentication, exposing systems to full compromise of confidentiality, integrity, and availability. The flaw is classified as CWE-798 and carries a critical CVSS 9.8 severity.
The issue was fixed in 9Router 0.4.44 by removing the hardcoded default secret and changing the application to load the signing key from the JWT_SECRET environment variable or a persisted file under ~/.9router/jwt-secret, generating a random 32-byte hex secret if none exists. Project updates also revised documentation to reflect the new secret-handling behavior and expanded protected API coverage to include /api/translator, reducing the risk of unauthorized access through improperly secured dashboard functions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability affecting 9Router versions 0.2.21 through before 0.4.44 was fixed in version 0.4.44. Advisory, release, and commit references for CVE-2026-49352 were published on July 15, 2026.
A GitHub commit changed 9Router's JWT handling to stop using the hardcoded default secret "9router-default-secret-change-me." The update instead loads a secret from the JWT_SECRET environment variable or a persisted file, and generates a random secret if none exists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.