<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-92717 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-92717/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 19:51:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-92717/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-92717 Authentication Bypass in Covenant</title><link>https://feed.craftedsignal.io/briefs/2026-09-covenant-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 19:51:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-covenant-auth-bypass/</guid><description>Covenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.</description><content:encoded><![CDATA[<p>Covenant versions 0.6 and earlier suffer from a critical authentication bypass vulnerability (CVE-2026-92717) due to a missing 'Authorize' attribute on the 'CovenantHub' SignalR hub. This oversight permits unauthenticated network callers to invoke the 'CreateHttpListener' method, which returns a valid signed JWT token. An attacker who successfully calls this method can use the returned token to authenticate against the Covenant operator API. This grants the attacker full control over the C2 infrastructure, including the ability to manage grunts, access stored credentials, modify binaries, and exfiltrate sensitive operational data and event logs. Because the vulnerability involves a core architectural flaw in the SignalR hub configuration, it significantly lowers the barrier for unauthorized parties to hijack a Covenant deployment. Defenders should prioritize patching or restricting access to the Covenant management interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows full administrative control over the Covenant C2 framework. An attacker can access all grunts, exfiltrate credentials gathered from target environments, modify or deploy malicious binaries, and retrieve operator roster and event history. This provides an attacker with the ability to maintain persistence, escalate privileges, and steal data harvested by the C2 platform.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to the Covenant management interface using network firewalls or VPNs until the software is updated.</li>
<li>Patch Covenant instances to a version addressing CVE-2026-92717 immediately.</li>
<li>Monitor SignalR traffic to the Covenant hub for unauthenticated calls to the 'CreateHttpListener' method.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authentication-bypass</category><category>c2-infrastructure</category><category>cve-2026-92717</category></item></channel></rss>