Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher. | |
| Title | Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-27T03:14:21.055Z
Reserved: 2026-07-24T05:29:02.405Z
Link: CVE-2026-16895
No data.
Status : Received
Published: 2026-08-27T04:16:41.530
Modified: 2026-08-27T04:16:41.530
Link: CVE-2026-16895
No data.
OpenCVE Enrichment
Updated: 2026-08-27T05:30:07Z
-
CWE-305
Authentication Bypass by Primary Weakness