CVE-2026-31983
Last modified
CVE-2026-31983 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nozominetworks | Cmc | < 26.2.0 |
| Nozominetworks | Guardian | < 26.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-31983?
How severe is CVE-2026-31983?
How do I fix CVE-2026-31983?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-31976xygeni-action is the GitHub Action for Xygeni Scanner. On Ma…9.8
- CVE-2026-31978motionEye (mEye) is an online interface for motion software,…6.5
- CVE-2026-31979Himmelblau is an interoperability suite for Microsoft Azure …7.8
- CVE-2026-3198MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails…6.5
- CVE-2026-31981A Stored HTML Injection vulnerability was discovered in the …4.8
- CVE-2026-31982An Open Redirect vulnerability was discovered in the SAML Si…7.1
- CVE-2026-31984A denial-of-service vulnerability caused by unbounded resour…8.7
- CVE-2026-31985When the upstream Guardian or CMC was configured in the Remo…8.3
- CVE-2026-31986Use of Hard-coded Cryptographic Key vulnerability in Apache …9.1
- CVE-2026-31987JWT Tokens used by tasks were exposed in logs. This could al…7.5
- CVE-2026-31988yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node…6.9
- CVE-2026-31989OpenClaw versions prior to 2026.3.1 contain a server-side re…6.3
Are you affected by CVE-2026-31983?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
