CVE-2026-6981
Last modified
CVE-2026-6981 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a manipulation results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6981?
How severe is CVE-2026-6981?
How do I fix CVE-2026-6981?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69804Time-of-check time-of-use (toctou) race condition in Microso…7.5
- CVE-2026-69805External control of file name or path in .NET allows an unau…7.5
- CVE-2026-69806Exposure of sensitive information to an unauthorized actor i…7
- CVE-2026-69807Improper limitation of a pathname to a restricted directory …8
- CVE-2026-69808Out-of-bounds read in Windows Win32K allows an authorized at…5.5
- CVE-2026-69809Missing release of memory after effective lifetime in Active…7.5
- CVE-2026-69813Use after free in Windows DNS allows an unauthorized attacke…8.1
- CVE-2026-69814Use after free in Windows Credential Providers allows an aut…7
- CVE-2026-69816Use after free in Windows Accounts Control allows an authori…7
- CVE-2026-69817Use after free in Windows Bluetooth Port Driver allows an au…7
- CVE-2026-69818Use after free in Windows Win32K allows an authorized attack…7
- CVE-2026-69819Out-of-bounds write in RPC Runtime allows an unauthorized at…9.8
Are you affected by CVE-2026-6981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
