{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-92717/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:covenant:covenant:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92717"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Covenant (\u003c= 0.6)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","c2-infrastructure","cve-2026-92717"],"_cs_type":"advisory","_cs_vendors":["Covenant"],"content_html":"\u003cp\u003eCovenant versions 0.6 and earlier suffer from a critical authentication bypass vulnerability (CVE-2026-92717) due to a missing 'Authorize' attribute on the 'CovenantHub' SignalR hub. This oversight permits unauthenticated network callers to invoke the 'CreateHttpListener' method, which returns a valid signed JWT token. An attacker who successfully calls this method can use the returned token to authenticate against the Covenant operator API. This grants the attacker full control over the C2 infrastructure, including the ability to manage grunts, access stored credentials, modify binaries, and exfiltrate sensitive operational data and event logs. Because the vulnerability involves a core architectural flaw in the SignalR hub configuration, it significantly lowers the barrier for unauthorized parties to hijack a Covenant deployment. Defenders should prioritize patching or restricting access to the Covenant management interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows full administrative control over the Covenant C2 framework. An attacker can access all grunts, exfiltrate credentials gathered from target environments, modify or deploy malicious binaries, and retrieve operator roster and event history. This provides an attacker with the ability to maintain persistence, escalate privileges, and steal data harvested by the C2 platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the Covenant management interface using network firewalls or VPNs until the software is updated.\u003c/li\u003e\n\u003cli\u003ePatch Covenant instances to a version addressing CVE-2026-92717 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor SignalR traffic to the Covenant hub for unauthenticated calls to the 'CreateHttpListener' method.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T19:51:18Z","date_published":"2026-09-16T19:51:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-covenant-auth-bypass/","summary":"Covenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.","title":"CVE-2026-92717 Authentication Bypass in Covenant","url":"https://feed.craftedsignal.io/briefs/2026-09-covenant-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-92717","version":"https://jsonfeed.org/version/1.1"}