Executive brief
SOCFortress CoPilot, a security operations management platform, contains a critical vulnerability where it uses a publicly known, hardcoded password to sign security tokens. Because this platform is designed to centralize control over various security tools (like Wazuh and Graylog), an attacker can use this known password to create their own administrative access tokens. This allows an unauthenticated person to take full control of the platform, access sensitive credentials for connected security systems, and potentially disable or manipulate the organization's entire security monitoring infrastructure.
Technical details
SOCFortress CoPilot prior to version 0.1.57 contains a hardcoded fallback value for the 'JWT_SECRET' in 'backend/app/auth/utils.py'. This secret is also provided verbatim in the '.env.example' file. In deployments where the administrator does not explicitly define a unique secret (including default Docker Compose installations), the application defaults to this publicly known value. An unauthenticated remote attacker can forge JSON Web Tokens (JWTs) with 'admin' scopes and 'sub=admin' claims. This leads to full administrative bypass, allowing the attacker to reset passwords, create backdoor accounts, and retrieve plaintext credentials for integrated security connectors (Wazuh, Graylog, etc.). The fix removes the fallback and implements a 'fail-fast' mechanism that prevents the application from starting if the compromised secret is detected.
Affected products
- SOCFortress CoPilot < 0.1.57
Timeline
- 2026-04-24: patched: Fix committed and advisory published on GitHub
- 2026-05-11: advisory: CVE published to NVD