CVE-2026-22096
Missing authentication for webserver endpoints
| CVE | CVE-2026-22096 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Title | Missing authentication for webserver endpoints | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Credits |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Affected products |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References |
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Problem type(s) | CWE-306 Missing Authentication for Critical Function | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Date published | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Last modified | 16 Jul 2026 15:41 UTC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or uploading files through different endpoints.
JSON version.