CVE-2026-107177highCWE-1394

CVE-2026-107177: high-severity vulnerability in ExpressGateway express-gateway

Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens

Published

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.4
exploitation probability
—
observed exploitation
nono source reports it
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token IDs to obtain valid bearer tokens for any user.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N