{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/the-momentum/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78154"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["open-wearables (0.6.2)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-78154","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["the-momentum"],"content_html":"\u003cp\u003eA vulnerability has been identified in the open-wearables application, specifically affecting versions up to and including 0.6.2. The flaw exists within the \u003ccode\u003eredeem_invitation_code\u003c/code\u003e function located in \u003ccode\u003ebackend/app/api/routes/v1/user_invitation_code.py\u003c/code\u003e. An attacker can exploit this vulnerability by manipulating the \u003ccode\u003ecode\u003c/code\u003e argument provided to the public invitation-code redemption endpoint. This action results in missing authentication, allowing unauthenticated remote parties to interact with critical functionality intended only for authorized users. The project maintainers have been notified via an issue report but have not provided a patch as of the reporting date. This vulnerability is classified as CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function).\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target running the open-wearables application (version 0.6.2 or earlier).\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the web interface to identify the public invitation-code redemption endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request targeting \u003ccode\u003ebackend/app/api/routes/v1/user_invitation_code.py\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker injects or manipulates the \u003ccode\u003ecode\u003c/code\u003e parameter within the request to bypass intended verification logic.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the identity of the requester due to the missing authentication check.\u003c/li\u003e\n\u003cli\u003eThe backend processes the invitation code without requiring valid user credentials.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized access to the invitation redemption process or underlying account features.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-78154 allows for unauthorized interaction with the invitation-code redemption endpoint. Given the nature of the vulnerability, this could lead to unauthorized account creation or access to features gated by invitation codes. Impacted sectors include any organization or individual utilizing the open-wearables platform for user management or registration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eInventory all assets running open-wearables and verify current versioning.\u003c/li\u003e\n\u003cli\u003eImplement access control lists (ACLs) or WAF rules to restrict traffic to the \u003ccode\u003e/api/routes/v1/user_invitation_code.py\u003c/code\u003e endpoint until a patch is available.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unexpected high volumes of requests to the invitation redemption endpoint, specifically looking for anomalous \u003ccode\u003ecode\u003c/code\u003e parameter values.\u003c/li\u003e\n\u003cli\u003eDisable the public invitation-code redemption endpoint if not required for business operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T01:40:09Z","date_published":"2026-08-24T01:40:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-open-wearables-auth-bypass/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-78154) in open-wearables versions 0.6.2 and earlier allows attackers to bypass authentication in the invitation code redemption endpoint.","title":"Authentication Bypass in open-wearables","url":"https://feed.craftedsignal.io/briefs/2026-08-open-wearables-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - The-Momentum","version":"https://jsonfeed.org/version/1.1"}