<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:aim:aim:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aaimaim/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 15:26:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aaimaim/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Aim Remote Tracking Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-aim-auth-bypass/</link><pubDate>Fri, 04 Sep 2026 15:26:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-aim-auth-bypass/</guid><description>The Aim remote tracking server version 3.29.1 contains an authentication bypass vulnerability allowing unauthenticated attackers to execute arbitrary methods and perform unauthorized data access or deletion.</description><content:encoded><![CDATA[<p>The Aim remote tracking server, specifically version 3.29.1, is affected by an authentication bypass vulnerability. The server fails to validate client requests and improperly dispatches arbitrary methods using the getattr function without an enforced allowlist. This flaw allows unauthenticated remote attackers to register new clients, instantiate Repo resources, and invoke unauthorized methods directly against the tracking server. Successful exploitation allows an attacker to manipulate sensitive experiment data, including reading private experiment logs or deleting recorded execution runs, potentially resulting in data loss or unauthorized exfiltration of model development telemetry. Defenders should prioritize restricting access to the Aim tracking server interface and monitoring for unauthorized API calls.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-85663 allows unauthenticated remote actors to gain control over the tracking server's resources. This can lead to the complete loss of experiment integrity, the unauthorized deletion of training runs, and the leakage of metadata related to machine learning projects.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to the Aim tracking server instance to authorized internal networks only.</li>
<li>Monitor web logs for unexpected POST requests directed at the Aim tracking server API endpoints that do not originate from known, authorized client IP addresses.</li>
<li>Upgrade to a version of Aim that enforces server-side authentication and request validation once the vendor releases a patch.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>authentication-bypass</category><category>cve-2026-85663</category></item></channel></rss>