<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SkillHub - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/skillhub/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 15:55:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/skillhub/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Account Takeover Vulnerability in SkillHub AccountMergeService</title><link>https://feed.craftedsignal.io/briefs/2026-10-skillhub-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 15:55:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-skillhub-auth-bypass/</guid><description>SkillHub versions prior to 0.2.22 contain an incorrect authorization vulnerability allowing authenticated attackers to perform account takeovers by exploiting the account merge flow.</description><content:encoded><![CDATA[<p>SkillHub versions prior to 0.2.22 contain a critical incorrect authorization vulnerability within the AccountMergeService and AccountMergeController components. This flaw allows an authenticated attacker to manipulate the account merge process to hijack the identity of another user. By submitting a crafted request to the merge initiation endpoint with a target username or OAuth identifier, an attacker can directly obtain the verification token required to complete the merge. Successfully exploiting this vulnerability grants the attacker full control over the victim's account, including the inheritance of associated API tokens, user roles, and namespace ownership. This represents a significant risk for multi-tenant environments or systems relying on SkillHub for centralized identity management, as it facilitates rapid privilege escalation and lateral movement across organizational resources.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains access to a low-privileged account within the SkillHub environment.</li>
<li>Attacker identifies the account merge initiation endpoint via API documentation or reverse engineering.</li>
<li>Attacker crafts an HTTP POST request targeting the merge service.</li>
<li>Attacker inserts the victim's username or OAuth identity into the request parameters.</li>
<li>The vulnerable AccountMergeService fails to validate the authorization of the requestor against the target identity.</li>
<li>Attacker intercepts the verification token returned by the server.</li>
<li>Attacker submits the verification token to the merge confirmation endpoint.</li>
<li>Attacker inherits the victim's privileges, gaining access to roles, API tokens, and namespace ownership.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete account takeover, resulting in unauthorized access to sensitive data, potential exfiltration of proprietary information via inherited API tokens, and administrative takeover of namespaces. The impact is significant for organizations utilizing SkillHub for integrated access control, as it allows attackers to bypass identity boundaries and assume the permissions of high-privilege users or service accounts.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Upgrade all instances of SkillHub to version 0.2.22 or later immediately to resolve CVE-2026-108550.</li>
<li>Audit logs for the account merge initiation and confirmation endpoints to identify anomalous spikes in account merge activity.</li>
<li>Review account permissions and namespace ownership logs for any suspicious modifications performed by non-admin users.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>