{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apikiwidbpika3.5.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pikiwidb:pika:3.5.7:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-84700"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pika (3.5.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PikiwiDB"],"content_html":"\u003cp\u003ePikiwiDB (Pika) version 3.5.7 contains a critical authentication bypass vulnerability (CVE-2026-84700) within its internal protobuf replication server. The service exposes a secondary port, calculated as the default client port plus 2000 (e.g., 11221 for a default port of 9221), which fails to properly enforce authentication. While the Pika 'requirepass' configuration is intended to protect the replication interface, only the MetaSync handler specifically validates credentials. The frame dispatcher (DealMessage) fails to verify authentication or session state before routing incoming messages, such as TrySync, DBSync, BinlogSync, and RemoveSlaveNode, to their respective handlers. Consequently, an unauthenticated remote attacker can connect directly to the exposed replication port to exfiltrate full-sync snapshots, monitor live write streams, or disrupt database replication by removing slave nodes, regardless of the security settings configured on the primary client interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized exfiltration of sensitive database content and full-sync snapshots, potentially leading to complete data exposure. Attackers can also disrupt database availability and integrity by force-removing legitimate replica nodes. This vulnerability affects Pika 3.5.7, which is often deployed in high-performance storage environments where data replication is critical.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict network access to the PikiwiDB replication port to authorized internal nodes only via firewall rules, as the service does not enforce authentication.\u003c/li\u003e\n\u003cli\u003eAudit environment configurations for Pika 3.5.7 deployments and restrict management/replication port exposure from public or untrusted network segments.\u003c/li\u003e\n\u003cli\u003eMonitor internal network traffic for unexpected connections originating from non-replica nodes to the calculated Pika replication port (default client port + 2000).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T05:11:29Z","date_published":"2026-09-02T05:11:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pikiwidb-auth-bypass/","summary":"PikiwiDB Pika 3.5.7 suffers from an authentication bypass in its protobuf replication server, allowing unauthenticated remote attackers to synchronize data and manipulate replica nodes.","title":"Authentication Bypass in PikiwiDB Pika Replication Server","url":"https://feed.craftedsignal.io/briefs/2026-09-pikiwidb-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pikiwidb:pika:3.5.7:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}