Retour à la veille

CVE-2026-108549

Publié : 10 octobre 2026
Modifié : 10 octobre 2026
Lien officiel NVD
Score CVSS
8.1
HIGH

Description détaillée

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Références et Patchs