
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1195 is a logic flaw (insufficient verification of data authenticity) in the JWT Token Handler of MineAdmin 1.x and 2.x, specifically in the refresh function at the /system/refresh endpoint. The vulnerability allows a remote, low-privileged attacker to forge a JWT signed as a super administrator and obtain a valid new token with administrator privileges. It was published on January 19–20, 2026, with a public proof-of-concept available at the time of disclosure. The vendor was contacted prior to disclosure but did not respond. CVSS v3.1 base score is 7.5 (High) per NIST NVD, while the CNA (VulDB) rates it 5.0 (Medium); CVSS v4.0 is rated 1.3 (Low) by VulDB (VulDB PoC, Red Hat CVE).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). The refresh method in MineAdmin's JWT Token Handler, located at /system/refresh, fails to properly validate the cryptographic signature of the incoming JWT before issuing a new token. An attacker can craft an arbitrary JWT payload — including claims that set the user as a super administrator (user_type: 100, id: 1) — with any desired expiration time, and submit it to the refresh endpoint without possessing a legitimately signed token. The system accepts the forged token and returns a new, valid, server-issued JWT with administrator privileges. The attack requires network access and low-level authentication context (e.g., any valid account or knowledge of the token format), and is rated high complexity due to the need to construct a valid-looking JWT structure (VulDB PoC).
Successful exploitation allows an attacker to obtain a legitimate administrator-level JWT token, effectively bypassing all access controls in the MineAdmin backend management system. With super administrator privileges, an attacker can access, modify, or delete sensitive data, manage user accounts, and potentially pivot to other systems or services integrated with the MineAdmin instance. The confidentiality, integrity, and availability of the affected system are all at high risk per NIST's CVSS v3.1 assessment (VulDB PoC, Red Hat CVE).
A public proof-of-concept exploit has been available since at least January 2026, published in a GitHub issue by the researcher SourByte05. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of widespread exploitation. No threat actor attribution or CISA KEV catalog listing has been identified. The CVE status is listed as "Unknown" and no in-the-wild exploitation has been confirmed as of the available data (VulDB PoC, Red Hat CVE).
body="MineAdmin" on tools like Fofa or Shodan. Note the default backend API port (9501).{"id": 1, "username": "superAdmin", "user_type": "100", "jwt_scene": "default"} with any desired iat, nbf, and exp values. Sign it with any key (the server does not validate the signature)./system/refresh with the forged JWT in the Authorization: Bearer <token> header and Content-Type: application/json;charset=UTF-8./system/user/info or other admin endpoints) and perform unauthorized actions including data access, user management, or further lateral movement (VulDB PoC)./system/refresh from IP addresses not associated with legitimate users, especially with JWTs containing user_type: 100 or username: superAdmin claims; repeated token refresh attempts from a single source./system/refresh requests followed immediately by privileged API calls (e.g., user management, configuration changes) from the same session; JWT payloads in logs with anomalous iat/exp timestamps (e.g., far-future expiration).The vendor has not responded to disclosure and no official patch has been released as of the available data. The researcher recommends forcing validation of the JWT signature in the refresh method to ensure only tokens signed with the server's secret key are accepted. As a workaround, administrators should restrict network access to the MineAdmin backend API port (default: 9501) to trusted IP ranges, implement rate limiting on the /system/refresh endpoint, and monitor logs for anomalous token refresh activity. Organizations should evaluate upgrading to a patched version if and when one becomes available (VulDB PoC).
The vulnerability was submitted to VulDB by researcher SourByte05, who also published the proof-of-concept on GitHub. The vendor (MineAdmin) did not respond to the coordinated disclosure attempt. Red Hat has tracked the CVE in their security advisory database. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Red Hat CVE, VulDB PoC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."