<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cc_connect:cc_connect:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acc_connectcc_connect/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 15:55:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acc_connectcc_connect/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in cc-connect MAX Platform Adapter</title><link>https://feed.craftedsignal.io/briefs/2026-10-max-adapter-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 15:55:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-max-adapter-auth-bypass/</guid><description>The MAX platform adapter in cc-connect version 1.5.0 and earlier allows unauthenticated attackers to forge webhook updates and execute arbitrary shell commands on the host system.</description><content:encoded><![CDATA[<p>The cc-connect application, specifically within the MAX platform adapter (platform/max/max.go), contains a critical missing authentication vulnerability (CVE-2026-108549). This vulnerability affects webhook mode when a webhook_secret is not configured. An attacker with network access to the webhook listener (default port 8080) can submit malicious, unauthenticated update payloads. By crafting these payloads to include administrative user_id values, an attacker can bypass authorization controls and invoke privileged functions, such as the /shell command, resulting in arbitrary command execution on the host operating system. This issue is particularly severe in environments where the service is exposed to the internet or untrusted internal networks without secondary authentication or restrictive network access control lists.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify active listeners on TCP port 8080.</li>
<li>Attacker interacts with the webhook listener to confirm the presence of the MAX platform adapter.</li>
<li>Attacker identifies that the target environment lacks a configured webhook_secret in the platform/max/max.go implementation.</li>
<li>Attacker constructs a malicious JSON payload mimicking a legitimate platform update.</li>
<li>Attacker includes a high-privilege or administrator user_id within the forged payload.</li>
<li>Attacker sends the payload to the /webhook endpoint (or equivalent listener path) via an HTTP POST request.</li>
<li>The application fails to validate the request origin or authenticity, processing the forged payload as authorized.</li>
<li>The adapter executes the requested privileged command, such as /shell, leading to full system compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote, unauthenticated attackers to gain arbitrary code execution on the underlying host. This could lead to full system takeover, sensitive data exfiltration, or persistence within the environment. All versions of cc-connect up to and including 1.5.0 are affected.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade cc-connect to a version beyond 1.5.0 that addresses the missing authentication in the MAX platform adapter immediately.</li>
<li>If an immediate upgrade is not possible, ensure a robust webhook_secret is configured to enforce authentication on all webhook requests.</li>
<li>Restrict network access to the webhook listener (default port 8080) to trusted IP addresses only using host-based firewalls or network security groups.</li>
<li>Enable and monitor webserver logs (HTTP access logs) for POST requests to the /webhook endpoint occurring from unknown or external IP addresses.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve</category><category>remote-code-execution</category></item></channel></rss>