{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cc-connect/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cc_connect:cc_connect:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-108549"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cc-connect (\u003c= 1.5.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["cc-connect"],"content_html":"\u003cp\u003eThe cc-connect application, specifically within the MAX platform adapter (platform/max/max.go), contains a critical missing authentication vulnerability (CVE-2026-108549). This vulnerability affects webhook mode when a webhook_secret is not configured. An attacker with network access to the webhook listener (default port 8080) can submit malicious, unauthenticated update payloads. By crafting these payloads to include administrative user_id values, an attacker can bypass authorization controls and invoke privileged functions, such as the /shell command, resulting in arbitrary command execution on the host operating system. This issue is particularly severe in environments where the service is exposed to the internet or untrusted internal networks without secondary authentication or restrictive network access control lists.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify active listeners on TCP port 8080.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the webhook listener to confirm the presence of the MAX platform adapter.\u003c/li\u003e\n\u003cli\u003eAttacker identifies that the target environment lacks a configured webhook_secret in the platform/max/max.go implementation.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious JSON payload mimicking a legitimate platform update.\u003c/li\u003e\n\u003cli\u003eAttacker includes a high-privilege or administrator user_id within the forged payload.\u003c/li\u003e\n\u003cli\u003eAttacker sends the payload to the /webhook endpoint (or equivalent listener path) via an HTTP POST request.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the request origin or authenticity, processing the forged payload as authorized.\u003c/li\u003e\n\u003cli\u003eThe adapter executes the requested privileged command, such as /shell, leading to full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to gain arbitrary code execution on the underlying host. This could lead to full system takeover, sensitive data exfiltration, or persistence within the environment. All versions of cc-connect up to and including 1.5.0 are affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade cc-connect to a version beyond 1.5.0 that addresses the missing authentication in the MAX platform adapter immediately.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, ensure a robust webhook_secret is configured to enforce authentication on all webhook requests.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the webhook listener (default port 8080) to trusted IP addresses only using host-based firewalls or network security groups.\u003c/li\u003e\n\u003cli\u003eEnable and monitor webserver logs (HTTP access logs) for POST requests to the /webhook endpoint occurring from unknown or external IP addresses.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T15:55:34Z","date_published":"2026-10-10T15:55:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-max-adapter-auth-bypass/","summary":"The MAX platform adapter in cc-connect version 1.5.0 and earlier allows unauthenticated attackers to forge webhook updates and execute arbitrary shell commands on the host system.","title":"Authentication Bypass in cc-connect MAX Platform Adapter","url":"https://feed.craftedsignal.io/briefs/2026-10-max-adapter-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cc-Connect","version":"https://jsonfeed.org/version/1.1"}