CVE-2026-82448

Source
https://cve.org/CVERecord?id=CVE-2026-82448
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82448.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82448
Published
2026-08-29T12:05:34.812Z
Modified
2026-09-02T03:30:37.949465272Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key
Details

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82448.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "5a76c74f3977661ff3f9fd55a260db352c0b19c0"
                }
            ]
        }
    ],
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-798"
    ]
}
References

Affected packages

Git / gitlab.com/shinobi-systems/shinobi

Affected ranges

Type
GIT
Repo
https://gitlab.com/shinobi-systems/shinobi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
furrykitten-3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82448.json"