knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 23:16
Updated : 2026-09-14 20:17
NVD link : CVE-2026-86543
Mitre link : CVE-2026-86543
CVE.ORG link : CVE-2026-86543
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
