{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/spikster/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-67594"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Spikster (\u003c= e1cdf8c)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-67594","rce"],"_cs_type":"advisory","_cs_vendors":["Spikster"],"content_html":"\u003cp\u003eSpikster, up to and including commit e1cdf8c, contains a critical security vulnerability (CVE-2026-67594) characterized by missing authentication on its API routes. The application includes a 'CipiAuth' middleware component intended to secure API access; however, this middleware is correctly registered within the application framework but never actually applied to any specific API route definitions.\u003c/p\u003e\n\u003cp\u003eAs a result, an unauthenticated remote attacker can interact with approximately 50 protected API endpoints. These endpoints provide extensive control over the managed environment, including the ability to provision new servers, reset administrative root passwords, perform arbitrary file read and write operations on the underlying host, and create new database users. Given the high-privileged nature of these actions, successful exploitation grants the attacker full control over the application and the host server, making this an extremely high-impact vulnerability for any infrastructure relying on Spikster for management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated access to system management functions, which can lead to complete server takeover, unauthorized data access, persistence through new database users, and arbitrary code execution via file write operations. This affects any deployment running Spikster versions up to commit e1cdf8c.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Spikster immediately to a version beyond commit e1cdf8c where the CipiAuth middleware is correctly applied to all API route groups.\u003c/li\u003e\n\u003cli\u003eAudit access logs for any unauthorized POST, PUT, or DELETE requests directed to administrative API endpoints that do not originate from authenticated sessions.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Spikster API interface to trusted management IP addresses only via a Web Application Firewall (WAF) or network ACLs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T21:31:30Z","date_published":"2026-07-30T21:31:30Z","id":"https://feed.craftedsignal.io/briefs/2026-07-spikster-auth-bypass/","summary":"A missing authentication vulnerability in Spikster allows unauthenticated remote attackers to access approximately 50 API endpoints, leading to full system compromise.","title":"Critical Authentication Bypass in Spikster API","url":"https://feed.craftedsignal.io/briefs/2026-07-spikster-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Spikster","version":"https://jsonfeed.org/version/1.1"}