Skip to content
Threat Feed
high advisory

Authentication Bypass in cc-connect MAX Platform Adapter

The MAX platform adapter in cc-connect version 1.5.0 and earlier allows unauthenticated attackers to forge webhook updates and execute arbitrary shell commands on the host system.

CVE search metadata

CVE search record: CVE-2026-108549. Severity: high. CVSS: 8.1. KEV: no. Product: cc-connect (<= 1.5.0). Brief: Authentication Bypass in cc-connect MAX Platform Adapter. Brief link: https://feed.craftedsignal.io/briefs/2026-10-max-adapter-auth-bypass/

The cc-connect application, specifically within the MAX platform adapter (platform/max/max.go), contains a critical missing authentication vulnerability (CVE-2026-108549). This vulnerability affects webhook mode when a webhook_secret is not configured. An attacker with network access to the webhook listener (default port 8080) can submit malicious, unauthenticated update payloads. By crafting these payloads to include administrative user_id values, an attacker can bypass authorization controls and invoke privileged functions, such as the /shell command, resulting in arbitrary command execution on the host operating system. This issue is particularly severe in environments where the service is exposed to the internet or untrusted internal networks without secondary authentication or restrictive network access control lists.

Attack Chain

  1. Attacker performs network reconnaissance to identify active listeners on TCP port 8080.
  2. Attacker interacts with the webhook listener to confirm the presence of the MAX platform adapter.
  3. Attacker identifies that the target environment lacks a configured webhook_secret in the platform/max/max.go implementation.
  4. Attacker constructs a malicious JSON payload mimicking a legitimate platform update.
  5. Attacker includes a high-privilege or administrator user_id within the forged payload.
  6. Attacker sends the payload to the /webhook endpoint (or equivalent listener path) via an HTTP POST request.
  7. The application fails to validate the request origin or authenticity, processing the forged payload as authorized.
  8. The adapter executes the requested privileged command, such as /shell, leading to full system compromise.

Impact

Successful exploitation allows remote, unauthenticated attackers to gain arbitrary code execution on the underlying host. This could lead to full system takeover, sensitive data exfiltration, or persistence within the environment. All versions of cc-connect up to and including 1.5.0 are affected.

Recommendation

  1. Upgrade cc-connect to a version beyond 1.5.0 that addresses the missing authentication in the MAX platform adapter immediately.
  2. If an immediate upgrade is not possible, ensure a robust webhook_secret is configured to enforce authentication on all webhook requests.
  3. Restrict network access to the webhook listener (default port 8080) to trusted IP addresses only using host-based firewalls or network security groups.
  4. Enable and monitor webserver logs (HTTP access logs) for POST requests to the /webhook endpoint occurring from unknown or external IP addresses.

Immediate actions

Patch or upgrade cc-connect to version > 1.5.0.

IT Operations 24h

Mitigations

Configure webhook_secret and restrict network access to port 8080.

immediate IT Operations

CVE-2026-108549

Detection coverage 1

Detect CVE-2026-108549 Exploitation - Unauthorized Webhook Access

high

Detects potential exploitation attempts of CVE-2026-108549 by identifying POST requests to the webhook listener that attempt to trigger shell functionality.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →