Sceawere
Vulnerability Detail
CVE-2026-102245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authentication in MODSetter SurfSense
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- MODSetter
- Product
- SurfSense
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-29T04:17:52.653Z",
"pubdate": "2026-09-29T04:17:52.653Z",
"executiveSummary": "A critical security vulnerability has been identified in MODSetter SurfSense versions up to 2.0.3, specifically concerning the circleback Endpoint.\nThe vulnerability is categorized as a missing authentication flaw, which permits unauthorized entities to interact with the backend service.\nThe affected component, located within surfsense_backend/app/routes/circleback_webhook_route.py, fails to implement sufficient access controls or verification mechanisms for incoming requests.\nThis vulnerability exposes the application to remote exploitation without requiring valid credentials or high-level privileges.\nGiven that exploit code has been made publicly available and the vendor has remained unresponsive to disclosure attempts, the risk of active exploitation is significant.\nSuccessful exploitation allows remote attackers to interact with the webhook route, potentially leading to unauthorized data processing, system state manipulation, or the triggering of backend logic intended for trusted services only.\nOrganizations utilizing SurfSense 2.0.3 or earlier are at an elevated risk of compromise and should treat this as a high-priority security concern.",
"technicalDetails": "The vulnerability exists within the circleback Endpoint of the MODSetter SurfSense application, specifically targeting the logic housed in surfsense_backend/app/routes/circleback_webhook_route.py.\nThe root cause is an absolute absence of authentication checks or cryptographic signature verification on the specified webhook route. In production environments, webhook endpoints are designed to receive external payloads from third-party services; however, these endpoints must validate the authenticity of the sender, typically through HMAC headers or pre-shared keys.\nIn the case of SurfSense, the route lacks a functional authentication layer, effectively exposing the backend to any actor capable of reaching the service via the network.\nThe attack flow proceeds as follows: An attacker identifies the accessible circleback endpoint on the public-facing instance of the application. Because the application does not perform a handshake or verify the integrity/origin of the incoming POST or GET requests, the attacker can craft arbitrary payloads. These payloads are processed directly by the backend logic defined in circleback_webhook_route.py.\nBy manipulating the request structure, an attacker can bypass intended security boundaries. Since the function performs no validation, the application executes the logic associated with the webhook trigger as if it were coming from an authorized source. This can lead to unauthorized data ingestion, the disruption of existing internal data sets, or the abuse of downstream functions triggered by the webhook.\nThe vulnerability is fully remote, requiring no local access or prior authentication, making it a high-utility target for automated scanning and exploitation scripts. The lack of response from the vendor means no official patch or security hardening configuration is currently available, leaving the vulnerability exposed in all affected versions up to 2.0.3.\nPost-exploitation impact varies depending on the specific functions triggered by the circleback route. If the route handles sensitive state changes or interacts with databases, the impact could range from unauthorized data modification to remote service compromise, depending on the privileges held by the service account executing the Python backend.\nGiven the public availability of the exploit, any endpoint exposed to the internet is susceptible to immediate exploitation by threat actors leveraging existing proof-of-concept scripts to probe for the lack of authentication."
}