CVE-2026-103397
Last modified
CVE-2026-103397 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations..
Description
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Liquid-co | OpenSave | < 2.4.0-beta.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103397?
How severe is CVE-2026-103397?
How do I fix CVE-2026-103397?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103353Incorrect Behavior Order vulnerability in WP ManageNinja LLC…5.3
- CVE-2026-103387A weakness has been identified in garycourt uri-js up to 4.4…4.3
- CVE-2026-103388MISP renders the source field of a Galaxy Cluster as a click…6.2
- CVE-2026-103389MISP contains a stored cross-site scripting (XSS) vulnerabil…6.2
- CVE-2026-103395LightLLM through 1.2.0 visual_only deployments expose an una…9.8
- CVE-2026-103396bbs-go through 4.4.6 contains a permission bypass vulnerabil…4.3
- CVE-2026-103398OpenSave through 2.4.0 fails to properly validate save paths…8.1
- CVE-2026-103399A flaw was found in SoupServer (libsoup). When an HTTP/1.x c…5.3
- CVE-2026-103431colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT…7.7
- CVE-2026-103432apcupsd through 3.14.14 has an sscanf stack-based buffer ove…8.1
- CVE-2026-103436apcupsd through 3.14.14 discloses uninitialized stack memory…3.7
- CVE-2026-103437Improper neutralization of Script-Related HTML tags in a web…1.1
Are you affected by CVE-2026-103397?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
