{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-82448/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:shinobi:shinobi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82448"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Shinobi (\u003c commit 5a76c74f)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-82448","sql-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Shinobi"],"content_html":"\u003cp\u003eShinobi versions released prior to commit 5a76c74f contain a significant security vulnerability involving a hardcoded connection key within the child node service. This vulnerability enables unauthenticated remote attackers to establish a WebSocket connection to the child node by providing the known hardcoded key during the handshake process. Once the handshake is successful, the attacker can leverage the 'onWebSocketDataFromChildNode' handler to dispatch arbitrary SQL queries against the underlying database. This allows for unauthorized data exfiltration, modification of user records, and manipulation of camera configurations. Because the vulnerability facilitates direct interaction with the database layer, it effectively grants full database access to any attacker with network connectivity to the child node port.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full database compromise, which may include the theft of user credentials, unauthorized viewing of camera feeds, and the ability to alter system configurations. This poses a critical risk to deployments where Shinobi nodes are exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Shinobi child node service to commit 5a76c74f or later immediately.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the child node service port (default WebSocket ports) to trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eAudit database logs for unusual query patterns or unexpected modifications to the 'users' and 'camera' tables that occur from the child node service interface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T13:38:50Z","date_published":"2026-08-29T13:38:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shinobi-hardcoded-key/","summary":"Shinobi versions prior to commit 5a76c74f contain a hardcoded connection key in the child node service, allowing unauthenticated attackers to execute arbitrary SQL queries.","title":"Hardcoded Connection Key Vulnerability in Shinobi Child Node","url":"https://feed.craftedsignal.io/briefs/2026-08-shinobi-hardcoded-key/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-82448","version":"https://jsonfeed.org/version/1.1"}