CVE-2026-104058

⚪ Do wiadomości

Brak uwierzytelnienia w Podgrab umożliwia atakującym przejęcie danych użytkowników.

CVSS
5.3
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-10-01 19:17:19 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:47:49 UTC
Referencje