CVE-2026-67594

Source
https://cve.org/CVERecord?id=CVE-2026-67594
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67594.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67594
Published
2026-07-30T19:14:27Z
Modified
2026-10-08T02:51:50Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Spikster Missing Authentication via API Route Group
Details

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root passwords, read and write arbitrary files on the host, and create database users.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67594.json"
}
References

Affected packages

Git / github.com/yolanmees/Spikster

Affected ranges

Type
GIT
Repo
https://github.com/yolanmees/Spikster
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67594.json"