{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cc-connect--1.5.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:feishu:cc-connect:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cc-connect (\u003c= 1.5.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authorization-bypass","cloud"],"_cs_type":"advisory","_cs_vendors":["Feishu"],"content_html":"\u003cp\u003eThe cc-connect application, specifically versions up to and including 1.5.0, contains an authorization bypass vulnerability (CVE-2026-92801) affecting the processing of Feishu interactive card callbacks. The vulnerability exists within the onCardAction handler, which fails to correctly enforce per-user allowlist filtering. In typical deployments, administrative or sensitive agent commands are protected by access control lists applied to standard text message handlers. However, by triggering interactive card actions within admitted chats, an attacker can bypass these security constraints. This allows unauthorized users to dispatch commands to the agent, potentially resulting in unauthorized execution of backend operations or information disclosure. The vulnerability is critical for organizations relying on granular access control within their Feishu-integrated chat agents, as the failure occurs at the integration logic layer rather than the platform level.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or unauthorized users to perform agent-level actions that were intended to be restricted to specific users. This undermines the security model of the integration, potentially leading to unauthorized data exfiltration or administrative command execution within the connected system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all instances of cc-connect within the environment and confirm the version is 1.5.0 or lower.\u003c/li\u003e\n\u003cli\u003eImplement an immediate block or restriction on Feishu interactive card callback endpoints until a patched version is deployed.\u003c/li\u003e\n\u003cli\u003eReview access logs for the onCardAction handler to identify anomalous interaction patterns originating from users not present on authorized allowlists.\u003c/li\u003e\n\u003cli\u003eMonitor for agent command execution logs that correlate with incoming interactive card callbacks from unauthorized accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T21:57:52Z","date_published":"2026-09-16T21:57:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92801/","summary":"The cc-connect application through version 1.5.0 contains an authorization bypass vulnerability in the onCardAction handler, allowing unprivileged users to execute unauthorized agent commands.","title":"Authorization Bypass in cc-connect via Interactive Card Callbacks","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-92801/"}],"language":"en","title":"CraftedSignal Threat Feed - Cc-Connect (\u003c= 1.5.0)","version":"https://jsonfeed.org/version/1.1"}