{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/easeprobe/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:megaease:easeprobe:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82815"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["EaseProbe (\u003c= 2.3.0)"],"_cs_severities":["medium"],"_cs_tags":["web-vulnerability","access-control","easeprobe"],"_cs_type":"advisory","_cs_vendors":["MegaEase"],"content_html":"\u003cp\u003eMegaEase EaseProbe versions up to 2.3.0 contain an improper access control vulnerability located within the \u003ccode\u003erealIP\u003c/code\u003e function of \u003ccode\u003eweb/server.go\u003c/code\u003e. This vulnerability allows a remote, unauthenticated attacker to manipulate specific HTTP request headers - namely \u003ccode\u003eX-Forwarded-For\u003c/code\u003e, \u003ccode\u003eX-Real-IP\u003c/code\u003e, and \u003ccode\u003eTrue-Client-IP\u003c/code\u003e - to bypass established access control policies. By spoofing these headers, an attacker can trick the application into incorrectly identifying the source IP address of the request. Since the vendor has not responded to disclosure efforts and public exploit code exists, organizations utilizing EaseProbe as a monitoring or middleware tool are at high risk of unauthorized access to administrative functions or protected resources.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to circumvent security policies and access protected application features without proper authorization. This can lead to unauthorized configuration changes, data exposure, or full compromise of the EaseProbe monitoring instance. The vulnerability affects all users of EaseProbe version 2.3.0 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network-level restrictions or a Web Application Firewall (WAF) to inspect and sanitize \u003ccode\u003eX-Forwarded-For\u003c/code\u003e, \u003ccode\u003eX-Real-IP\u003c/code\u003e, and \u003ccode\u003eTrue-Client-IP\u003c/code\u003e headers for traffic destined to EaseProbe instances.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious header manipulation patterns, such as unexpected IP addresses or anomalous patterns in requests to administrative endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict access to the EaseProbe management interface to trusted internal networks or via VPN until a vendor-supplied patch is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T19:58:39Z","date_published":"2026-08-31T19:58:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-easeprobe-access-control/","summary":"MegaEase EaseProbe versions up to 2.3.0 are vulnerable to remote access control bypass via manipulation of HTTP headers including X-Forwarded-For, X-Real-IP, and True-Client-IP.","title":"Improper Access Control in MegaEase EaseProbe","url":"https://feed.craftedsignal.io/briefs/2026-08-easeprobe-access-control/"}],"language":"en","title":"CraftedSignal Threat Feed - Easeprobe","version":"https://jsonfeed.org/version/1.1"}