CVE-2026-92717

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 18:17

Updated : 2026-09-16 18:17


NVD link : CVE-2026-92717

Mitre link : CVE-2026-92717

CVE.ORG link : CVE-2026-92717


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function