Description
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
Published: 2026-10-10
Score: 9.2 Critical
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Chenhg5
Chenhg5 cc-connect
Vendors & Products Chenhg5
Chenhg5 cc-connect

Sat, 10 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
Title cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Chenhg5 Cc-connect
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T14:35:04.291Z

Reserved: 2026-10-10T14:24:42.862Z

Link: CVE-2026-108549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-10T15:16:57.973

Modified: 2026-10-10T15:16:58.087

Link: CVE-2026-108549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T15:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function