{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ground-station--0.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ground-station:ground-station:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-103244"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ground-station (\u003c 0.8.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ground-station"],"content_html":"\u003cp\u003eGround-station versions prior to 0.8.0 contain a critical authentication bypass vulnerability (CVE-2026-103244) located within the setup.restore command. This flaw specifically affects the application's first-run setup mode when exposed via Socket.IO. An unauthenticated attacker can leverage this command to execute arbitrary SQL queries against the underlying database. By doing so, they can manually inject administrative user accounts into the system and forge valid session tokens, effectively bypassing all authentication mechanisms. Successful exploitation grants the attacker full administrative access to the application. This vulnerability is particularly dangerous in environments where the setup mode is not restricted or is left accessible post-deployment. Defenders should prioritize updating ground-station to version 0.8.0 or later and ensure that the installation setup process is strictly locked down after initial configuration.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a ground-station instance that has not completed its initial configuration or retains access to the setup mode.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a connection to the application's Socket.IO endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the setup.restore command by sending a specifically crafted request through the socket.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, failing to validate the requestor's authentication status.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious SQL command payload through the setup.restore parameters.\u003c/li\u003e\n\u003cli\u003eThe backend executes the SQL query, inserting a new administrative user record into the database.\u003c/li\u003e\n\u003cli\u003eAttacker uses the injected credentials to generate or forge a valid administrative session token.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates as an administrator, completing the full takeover of the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-103244 results in a complete compromise of the ground-station instance. Attackers gain full administrative control, which allows for the exfiltration of sensitive configuration data, manipulation of application settings, and potential lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all ground-station instances to version 0.8.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview network access control lists to ensure the Socket.IO endpoints are not exposed to untrusted networks.\u003c/li\u003e\n\u003cli\u003eInspect audit logs for unauthorized administrative account creation occurring outside of documented maintenance windows.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T12:41:14Z","date_published":"2026-10-01T12:41:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ground-station-auth-bypass/","summary":"Ground-station versions prior to 0.8.0 are susceptible to an authentication bypass vulnerability in the setup.restore command, allowing unauthenticated attackers to execute arbitrary SQL, inject admin users, and achieve full application takeover.","title":"Authentication Bypass in Ground-Station via setup.restore","url":"https://feed.craftedsignal.io/briefs/2026-10-ground-station-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Ground-Station (\u003c 0.8.0)","version":"https://jsonfeed.org/version/1.1"}