Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chenhg5
Chenhg5 cc-connect |
|
| Vendors & Products |
Chenhg5
Chenhg5 cc-connect |
Sat, 10 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host. | |
| Title | cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T14:35:04.291Z
Reserved: 2026-10-10T14:24:42.862Z
Link: CVE-2026-108549
No data.
Status : Deferred
Published: 2026-10-10T15:16:57.973
Modified: 2026-10-10T15:16:58.087
Link: CVE-2026-108549
No data.
OpenCVE Enrichment
Updated: 2026-10-10T15:30:17Z
-
CWE-306
Missing Authentication for Critical Function