{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3askillhubskillhub/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:skillhub:skillhub:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-108550"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SkillHub (\u003c 0.2.22)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SkillHub"],"content_html":"\u003cp\u003eSkillHub versions prior to 0.2.22 contain a critical incorrect authorization vulnerability within the AccountMergeService and AccountMergeController components. This flaw allows an authenticated attacker to manipulate the account merge process to hijack the identity of another user. By submitting a crafted request to the merge initiation endpoint with a target username or OAuth identifier, an attacker can directly obtain the verification token required to complete the merge. Successfully exploiting this vulnerability grants the attacker full control over the victim's account, including the inheritance of associated API tokens, user roles, and namespace ownership. This represents a significant risk for multi-tenant environments or systems relying on SkillHub for centralized identity management, as it facilitates rapid privilege escalation and lateral movement across organizational resources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a low-privileged account within the SkillHub environment.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the account merge initiation endpoint via API documentation or reverse engineering.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the merge service.\u003c/li\u003e\n\u003cli\u003eAttacker inserts the victim's username or OAuth identity into the request parameters.\u003c/li\u003e\n\u003cli\u003eThe vulnerable AccountMergeService fails to validate the authorization of the requestor against the target identity.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the verification token returned by the server.\u003c/li\u003e\n\u003cli\u003eAttacker submits the verification token to the merge confirmation endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inherits the victim's privileges, gaining access to roles, API tokens, and namespace ownership.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete account takeover, resulting in unauthorized access to sensitive data, potential exfiltration of proprietary information via inherited API tokens, and administrative takeover of namespaces. The impact is significant for organizations utilizing SkillHub for integrated access control, as it allows attackers to bypass identity boundaries and assume the permissions of high-privilege users or service accounts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of SkillHub to version 0.2.22 or later immediately to resolve CVE-2026-108550.\u003c/li\u003e\n\u003cli\u003eAudit logs for the account merge initiation and confirmation endpoints to identify anomalous spikes in account merge activity.\u003c/li\u003e\n\u003cli\u003eReview account permissions and namespace ownership logs for any suspicious modifications performed by non-admin users.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T15:55:44Z","date_published":"2026-10-10T15:55:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-skillhub-auth-bypass/","summary":"SkillHub versions prior to 0.2.22 contain an incorrect authorization vulnerability allowing authenticated attackers to perform account takeovers by exploiting the account merge flow.","title":"Account Takeover Vulnerability in SkillHub AccountMergeService","url":"https://feed.craftedsignal.io/briefs/2026-10-skillhub-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:skillhub:skillhub:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}