{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/meshcentral-1.1.21/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-66420"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MeshCentral (1.1.21)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MeshCentral"],"content_html":"\u003cp\u003eMeshCentral version 1.1.21 is vulnerable to a cross-site WebSocket hijacking protection bypass (CVE-2026-66420). The vulnerability is rooted in an unconditional early return within the CheckWebServerOriginName() function located in webserver.js, which is triggered when the instance is configured to use self-signed certificates. Because of this logic error, the application fails to validate the origin of incoming WebSocket connections.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can leverage this flaw by initiating cross-origin WebSocket requests to any of the twelve available MeshCentral WebSocket endpoints. By sending crafted action commands, an attacker can exfiltrate the server sessionKey. Possession of this key allows the attacker to forge session tokens for arbitrary users, including administrators, effectively granting full remote control over the MeshCentral server and all managed endpoints. This vulnerability is particularly critical for deployments relying on default or self-signed certificate configurations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a complete compromise of the MeshCentral management server. Attackers gain the ability to forge administrator sessions, bypass authentication, and exercise full remote control over every device managed by the affected instance. This represents a significant risk for organizations managing large fleets of remote assets, as it permits lateral movement, data exfiltration, and persistent access to the managed infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all MeshCentral instances to a version where this vulnerability is remediated.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, transition from self-signed certificates to certificates signed by a trusted Certificate Authority (CA) to prevent the trigger of the flawed code path.\u003c/li\u003e\n\u003cli\u003eReview access logs for unusual cross-origin requests targeting WebSocket endpoints, particularly those originating from external domains.\u003c/li\u003e\n\u003cli\u003eConduct a full audit of all managed devices and active sessions if the MeshCentral instance is suspected of having been compromised.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T23:32:35Z","date_published":"2026-07-30T23:32:35Z","id":"https://feed.craftedsignal.io/briefs/2026-07-meshcentral-websocket-hijacking/","summary":"CVE-2026-66420 is a high-severity vulnerability in MeshCentral 1.1.21 allowing unauthenticated attackers to hijack administrator sessions via a cross-site WebSocket hijacking protection bypass.","title":"MeshCentral WebSocket Hijacking Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-meshcentral-websocket-hijacking/"}],"language":"en","title":"CraftedSignal Threat Feed - MeshCentral (1.1.21)","version":"https://jsonfeed.org/version/1.1"}