CVE-2026-1114 affects parisneo/lollms versions prior to 2.2.0 and involves a critical session management flaw in JWT implementation. The application uses a weak secret key for signing JSON Web Tokens, enabling attackers to conduct offline brute-force attacks to recover the key and subsequently forge administrative tokens by modifying JWT payloads. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector requiring no authentication, user interaction, or special privileges. Once exploited, the flaw grants attackers complete confidentiality, integrity, and availability compromise through unauthorized administrative access and privilege escalation to restricted endpoints. Current exploitation status indicates the vulnerability is not being actively exploited in the wild, with no known public exploit code readily available. The vulnerability carries a low EPSS score of 0.000190000 and is not included on the CISA Known Exploited Vulnerabilities catalog, suggesting minimal community attention and exploitation attempts at this time. Organizations running lollms should prioritize upgrading to version 2.2.0 to remediate this critical issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0CPE matchmatch criteria | cpe:2.3:a:lollms:lollms:2.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.