CVE-2026-104058
⚪ Do wiadomości
Brak uwierzytelnienia w Podgrab umożliwia atakującym przejęcie danych użytkowników.
CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-10-01 19:17:19 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:47:49 UTC |