Authentication Bypass in Ground-Station via setup.restore
Ground-station versions prior to 0.8.0 are susceptible to an authentication bypass vulnerability in the setup.restore command, allowing unauthenticated attackers to execute arbitrary SQL, inject admin users, and achieve full application takeover.
CVE search metadata
CVE search record: CVE-2026-103244. Severity: critical. CVSS: 9.8. KEV: no. Product: ground-station (< 0.8.0). Brief: Authentication Bypass in Ground-Station via setup.restore. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ground-station-auth-bypass/
Ground-station versions prior to 0.8.0 contain a critical authentication bypass vulnerability (CVE-2026-103244) located within the setup.restore command. This flaw specifically affects the application's first-run setup mode when exposed via Socket.IO. An unauthenticated attacker can leverage this command to execute arbitrary SQL queries against the underlying database. By doing so, they can manually inject administrative user accounts into the system and forge valid session tokens, effectively bypassing all authentication mechanisms. Successful exploitation grants the attacker full administrative access to the application. This vulnerability is particularly dangerous in environments where the setup mode is not restricted or is left accessible post-deployment. Defenders should prioritize updating ground-station to version 0.8.0 or later and ensure that the installation setup process is strictly locked down after initial configuration.
Attack Chain
- Attacker identifies a ground-station instance that has not completed its initial configuration or retains access to the setup mode.
- Attacker initiates a connection to the application's Socket.IO endpoint.
- Attacker triggers the setup.restore command by sending a specifically crafted request through the socket.
- The application processes the request, failing to validate the requestor's authentication status.
- Attacker injects a malicious SQL command payload through the setup.restore parameters.
- The backend executes the SQL query, inserting a new administrative user record into the database.
- Attacker uses the injected credentials to generate or forge a valid administrative session token.
- Attacker authenticates as an administrator, completing the full takeover of the application.
Impact
Successful exploitation of CVE-2026-103244 results in a complete compromise of the ground-station instance. Attackers gain full administrative control, which allows for the exfiltration of sensitive configuration data, manipulation of application settings, and potential lateral movement within the environment.
Recommendation
- Upgrade all ground-station instances to version 0.8.0 or later immediately.
- Review network access control lists to ensure the Socket.IO endpoints are not exposed to untrusted networks.
- Inspect audit logs for unauthorized administrative account creation occurring outside of documented maintenance windows.
Immediate actions
Upgrade ground-station to 0.8.0 or later.
Mitigations
Disable access to the setup mode or restrict network access to the Socket.IO port if patching is delayed.
CVE-2026-103244