CVE-2026-82448
Last modified
CVE-2026-82448 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Shinobi Systems | Shinobi | < 5a76c74f3977661ff3f9fd55a260db352c0b19c0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82448?
How severe is CVE-2026-82448?
How do I fix CVE-2026-82448?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82422A security flaw has been discovered in itsourcecode Sales an…6.3
- CVE-2026-82423A vulnerability has been found in macrozheng mall up to 1.0.…5.4
- CVE-2026-82424A weakness has been identified in PHPGurukul Student Informa…6.3
- CVE-2026-8243A vulnerability was determined in Industrial Application Sof…6.9
- CVE-2026-8244A vulnerability was identified in Industrial Application Sof…5.5
- CVE-2026-82447Skyvern before 1.0.45 contains a sandbox escape vulnerabilit…8.8
- CVE-2026-82449Cockpit CMS before 2.14.1 contains an account enumeration vu…5.3
- CVE-2026-8245Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS …5.4
- CVE-2026-82450BookStack before 26.05.4 contains a remote code execution vu…8.8
- CVE-2026-82451Formwork before 2.3.11 contains a stored cross-site scriptin…6.1
- CVE-2026-82452rust-iot-platform through commit 5df942ab contains an authen…9.8
- CVE-2026-82453rust-iot-platform through commit 5df942ab stores user passwo…7.5
Are you affected by CVE-2026-82448?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
