CVE-2026-86543

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 23:16

Updated : 2026-09-14 20:17


NVD link : CVE-2026-86543

Mitre link : CVE-2026-86543

CVE.ORG link : CVE-2026-86543


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function