{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/unmaintained-software/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vvbbnn00:warp_clash_api:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90504"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WARP-Clash-API (\u003c= c7bf2360073959861219b422e51ae86411051b46)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","api-security","unmaintained-software"],"_cs_type":"advisory","_cs_vendors":["vvbbnn00"],"content_html":"\u003cp\u003eCVE-2026-90504 is a high-severity authentication bypass vulnerability affecting the vvbbnn00 WARP-Clash-API, specifically within the 'authorized' function. The vulnerability stems from improper handling of the SECRET_KEY argument, which allows a remote, unauthenticated attacker to bypass security controls. The issue exists in all versions up to commit hash c7bf2360073959861219b422e51ae86411051b46. Because the software is no longer maintained and the vendor did not respond to disclosure, no official security patch is available. Defenders should prioritize identifying and decommissioning instances of this software, as exploitation is publicly documented and does not require complex prerequisites.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a complete failure of authentication for the affected API. An attacker successfully exploiting this flaw can gain unauthorized access to the application, potentially leading to unauthorized data access, system manipulation, or further exploitation of underlying infrastructure depending on the API's permissions. Given the product's unmaintained status, affected systems remain permanently exposed to this risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform a network discovery scan to identify any instances of WARP-Clash-API running in the environment.\u003c/li\u003e\n\u003cli\u003eDecommission or isolate all identified instances of this software immediately, as no patch exists to mitigate the vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access controls to restrict access to the API endpoints to authorized management IP addresses only, pending full removal.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T11:25:01Z","date_published":"2026-09-13T11:25:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-warp-clash-api-auth-bypass/","summary":"A publicly disclosed vulnerability in the WARP-Clash-API authorized function allows remote unauthenticated access by manipulating the SECRET_KEY argument.","title":"Authentication Bypass in WARP-Clash-API via SECRET_KEY Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-09-warp-clash-api-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Unmaintained-Software","version":"https://jsonfeed.org/version/1.1"}