<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vvbbnn00:warp_clash_api:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avvbbnn00warp_clash_api/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 11:25:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avvbbnn00warp_clash_api/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation</title><link>https://feed.craftedsignal.io/briefs/2026-09-warp-clash-api-auth-bypass/</link><pubDate>Sun, 13 Sep 2026 11:25:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-warp-clash-api-auth-bypass/</guid><description>A publicly disclosed vulnerability in the WARP-Clash-API authorized function allows remote unauthenticated access by manipulating the SECRET_KEY argument.</description><content:encoded><![CDATA[<p>CVE-2026-90504 is a high-severity authentication bypass vulnerability affecting the vvbbnn00 WARP-Clash-API, specifically within the 'authorized' function. The vulnerability stems from improper handling of the SECRET_KEY argument, which allows a remote, unauthenticated attacker to bypass security controls. The issue exists in all versions up to commit hash c7bf2360073959861219b422e51ae86411051b46. Because the software is no longer maintained and the vendor did not respond to disclosure, no official security patch is available. Defenders should prioritize identifying and decommissioning instances of this software, as exploitation is publicly documented and does not require complex prerequisites.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a complete failure of authentication for the affected API. An attacker successfully exploiting this flaw can gain unauthorized access to the application, potentially leading to unauthorized data access, system manipulation, or further exploitation of underlying infrastructure depending on the API's permissions. Given the product's unmaintained status, affected systems remain permanently exposed to this risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform a network discovery scan to identify any instances of WARP-Clash-API running in the environment.</li>
<li>Decommission or isolate all identified instances of this software immediately, as no patch exists to mitigate the vulnerability.</li>
<li>Implement strict network-level access controls to restrict access to the API endpoints to authorized management IP addresses only, pending full removal.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>api-security</category><category>unmaintained-software</category></item></channel></rss>