Security
Loading…

CVE-2026-86543

CRITICALCVSS 9.8
Description

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.

Timeline
Published:September 7th, 2026 11:16 PM
Last modified:September 7th, 2026 11:16 PM
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute