Skip to content
Threat Feed
high advisory

Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation

A publicly disclosed vulnerability in the WARP-Clash-API authorized function allows remote unauthenticated access by manipulating the SECRET_KEY argument.

CVE search metadata

CVE search record: CVE-2026-90504. Severity: high. CVSS: 7.3. KEV: no. Product: WARP-Clash-API (<= c7bf2360073959861219b422e51ae86411051b46). Brief: Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation. Brief link: https://feed.craftedsignal.io/briefs/2026-09-warp-clash-api-auth-bypass/

CVE-2026-90504 is a high-severity authentication bypass vulnerability affecting the vvbbnn00 WARP-Clash-API, specifically within the 'authorized' function. The vulnerability stems from improper handling of the SECRET_KEY argument, which allows a remote, unauthenticated attacker to bypass security controls. The issue exists in all versions up to commit hash c7bf2360073959861219b422e51ae86411051b46. Because the software is no longer maintained and the vendor did not respond to disclosure, no official security patch is available. Defenders should prioritize identifying and decommissioning instances of this software, as exploitation is publicly documented and does not require complex prerequisites.

Impact

The vulnerability results in a complete failure of authentication for the affected API. An attacker successfully exploiting this flaw can gain unauthorized access to the application, potentially leading to unauthorized data access, system manipulation, or further exploitation of underlying infrastructure depending on the API's permissions. Given the product's unmaintained status, affected systems remain permanently exposed to this risk.

Recommendation

  • Perform a network discovery scan to identify any instances of WARP-Clash-API running in the environment.
  • Decommission or isolate all identified instances of this software immediately, as no patch exists to mitigate the vulnerability.
  • Implement strict network-level access controls to restrict access to the API endpoints to authorized management IP addresses only, pending full removal.

Immediate actions

Inventory and decommission all deployments of WARP-Clash-API

IT Operations 48h

Mitigations

Isolate affected instances via network firewall rules

immediate SOC

CVE-2026-90504