Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster. | |
| Title | Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub | |
| First Time appeared |
Cobbr
Cobbr covenant |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:cobbr:covenant:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cobbr
Cobbr covenant |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T17:31:37.704Z
Reserved: 2026-09-16T17:20:10.124Z
Link: CVE-2026-92717
No data.
Status : Received
Published: 2026-09-16T18:17:22.540
Modified: 2026-09-16T18:17:22.540
Link: CVE-2026-92717
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function