Sceawere

Vulnerability Detail

CVE-2026-108549UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Missing Authentication in cc-connect

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
chenhg5
Product
cc-connect
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-10T15:16:57.973Z",
  "pubdate": "2026-10-10T15:16:57.973Z",
  "executiveSummary": "The vulnerability identified in cc-connect, affecting versions through 1.5.0, is a critical missing authentication flaw localized within the MAX platform adapter's webhook implementation. This security deficiency allows unauthenticated remote adversaries to interact with the webhook listener on port 8080 by bypassing identity verification mechanisms when the webhook_secret configuration is omitted.\nThe flaw stems from an insecure design pattern where the application fails to validate incoming requests in the absence of a secret token. This failure effectively turns a private listener into an externally accessible endpoint susceptible to arbitrary request forgery. By crafting malicious payloads, an attacker can impersonate legitimate users or administrative accounts, potentially leading to full system compromise. The primary risk implication is that any remote entity capable of reaching the service port can manipulate the host environment, circumventing intended access controls and executing privileged commands. This represents a complete breakdown of trust boundaries, necessitating immediate remediation to prevent unauthorized remote code execution and systemic escalation.",
  "technicalDetails": "The vulnerability resides in the platform/max/max.go file within the MAX platform adapter component of the cc-connect ecosystem. The root cause is an implementation oversight in the webhook handler logic, which fails to enforce mandatory authentication checks when the 'webhook_secret' parameter is left unconfigured. In this state, the listener, which defaults to port 8080, treats all incoming HTTP POST requests as trusted input.\nThe exploitation flow begins with a remote attacker identifying an instance of cc-connect where the 'webhook_secret' has not been defined. The attacker targets the exposed webhook endpoint reachable on port 8080. Because the application logic does not verify the authenticity or origin of the webhook payload, it processes the request body blindly. An attacker can craft a forged JSON update payload specifying an arbitrary 'user_id'—specifically targeting accounts with 'admin' privileges—to bypass the internal security model.\nOnce the forged update is processed, the application grants the attacker the associated user context, allowing them to interface with restricted internal functions. Specifically, the vulnerability exposes the ability to trigger administrative commands, such as the '/shell' command, directly on the host operating system. This leads to arbitrary command execution with the privileges of the underlying service process.\nThe impact of this exploit is severe, as it grants unauthenticated remote actors the ability to execute arbitrary system commands. Since this requires no prior authentication or administrative authorization—provided the secret is missing—the attack surface is effectively open to any user with network visibility to the service. The payload behaves as a spoofed webhook trigger, convincing the internal state machine that a privileged event has occurred, which then executes the shell-level operation. Post-exploitation, an attacker can maintain persistence, exfiltrate sensitive data, or utilize the host as a pivot point for further lateral movement within the network infrastructure. Affected versions include all iterations up to and including 1.5.0, necessitating a review of the authentication logic in the MAX adapter code to ensure that requests are dropped by default unless cryptographic verification succeeds."
}
CVE-2026-108549: Missing Authentication in cc-connect (HIGH Severity, CVSS: 8.1) | Sceawere