{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rconfig--8.2.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rConfig (\u003c 8.2.13)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","web-application","authentication-bypass","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["rConfig"],"content_html":"\u003cp\u003eThe vulnerability CVE-2026-77915 affects rConfig versions prior to 8.2.13. The issue stems from a redundant \u003ccode\u003eAuth::routes()\u003c/code\u003e call within the \u003ccode\u003eroutes/web.php\u003c/code\u003e file, which inadvertently re-enables the registration endpoint after it had been explicitly disabled by the developers. When an unauthenticated attacker accesses the \u003ccode\u003e/register\u003c/code\u003e endpoint and creates a new account, the application fails to assign a restricted role during the account creation process. Consequently, the \u003ccode\u003eusers.role\u003c/code\u003e column in the underlying database defaults to the 'Admin' privilege level. This flaw allows an attacker to achieve full administrative access without prior authentication, providing them with the ability to manage device configurations, harvest sensitive credentials stored within the application, access user data, and generate new API tokens for further persistence. This vulnerability is critical due to the ease of exploitation and the resulting high-privileged access granted to unauthorized users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to obtain full administrative control over the rConfig instance. This access exposes the entirety of the network device management environment, including administrative credentials for managed network infrastructure, sensitive user information, and application API keys. Compromise of an rConfig instance could lead to widespread unauthorized access or configuration changes across the target organization's network devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update rConfig instances to version 8.2.13 or later to patch the registration route conflict.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for any entries created or modified after the date the application was deployed, specifically looking for users with 'Admin' roles created through the registration controller.\u003c/li\u003e\n\u003cli\u003eReview all API tokens for unexpected or suspicious issuance and revoke any tokens associated with unauthorized administrative accounts.\u003c/li\u003e\n\u003cli\u003eDeploy the provided webserver detection rule to monitor for unauthorized access attempts to the \u003ccode\u003e/register\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T18:03:19Z","date_published":"2026-08-24T18:03:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rconfig-auth-bypass/","summary":"rConfig versions 8.0.0 through 8.2.12 contain a logic flaw in route configuration that enables unauthenticated registration of administrator-privileged accounts, facilitating full system compromise.","title":"Authentication Bypass and Privilege Escalation in rConfig","url":"https://feed.craftedsignal.io/briefs/2026-08-rconfig-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - RConfig (\u003c 8.2.13)","version":"https://jsonfeed.org/version/1.1"}