{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aim-3.29.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aim:aim:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85663"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Aim (3.29.1)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication-bypass","cve-2026-85663"],"_cs_type":"advisory","_cs_vendors":["Aim"],"content_html":"\u003cp\u003eThe Aim remote tracking server, specifically version 3.29.1, is affected by an authentication bypass vulnerability. The server fails to validate client requests and improperly dispatches arbitrary methods using the getattr function without an enforced allowlist. This flaw allows unauthenticated remote attackers to register new clients, instantiate Repo resources, and invoke unauthorized methods directly against the tracking server. Successful exploitation allows an attacker to manipulate sensitive experiment data, including reading private experiment logs or deleting recorded execution runs, potentially resulting in data loss or unauthorized exfiltration of model development telemetry. Defenders should prioritize restricting access to the Aim tracking server interface and monitoring for unauthorized API calls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-85663 allows unauthenticated remote actors to gain control over the tracking server's resources. This can lead to the complete loss of experiment integrity, the unauthorized deletion of training runs, and the leakage of metadata related to machine learning projects.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the Aim tracking server instance to authorized internal networks only.\u003c/li\u003e\n\u003cli\u003eMonitor web logs for unexpected POST requests directed at the Aim tracking server API endpoints that do not originate from known, authorized client IP addresses.\u003c/li\u003e\n\u003cli\u003eUpgrade to a version of Aim that enforces server-side authentication and request validation once the vendor releases a patch.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:07Z","date_published":"2026-09-04T15:26:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aim-auth-bypass/","summary":"The Aim remote tracking server version 3.29.1 contains an authentication bypass vulnerability allowing unauthenticated attackers to execute arbitrary methods and perform unauthorized data access or deletion.","title":"Authentication Bypass in Aim Remote Tracking Server","url":"https://feed.craftedsignal.io/briefs/2026-09-aim-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Aim (3.29.1)","version":"https://jsonfeed.org/version/1.1"}