CVE-2025-56749

Publication date

2025-10-15 00:00:00

Family

mitre

State

PUBLISHED

Description

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.