Executive brief
yfexam-exam is an open-source online examination system. The application generates JWT authentication tokens using a predictable method based on the username and current month, rather than a cryptographically secure random key. An attacker can forge valid authentication tokens for any user account, including the default administrator account, without knowing the password, enabling complete account takeover and system compromise.
Technical details
The vulnerability is a weak JWT secret derivation flaw in the JwtUtils.encryptSecret() function. The signing secret is computed as MD5(username + "&" + MD5(username + "&" + MONTH)), where MONTH is Calendar.MONTH (0–11). Because the username is transmitted unverified in the JWT and the month is only a 12-value integer, an attacker can brute-force the secret by trying all 12 possible month values. The attack requires network access to the API endpoints (typically port 8101) and knowledge of a valid username (the default super admin account "admin" is well-known). An authenticated attacker can forge arbitrary JWTs for any user and bypass authentication entirely, leading to account takeover and privilege escalation. No authentication or user interaction is required beyond basic network reachability to the API.
Affected products
- yf-coder yfexam-exam v2.0, v1.0.0
Timeline
- 2026-09-08: disclosed: CVE-2026-79575 published