{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/webhood/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:webhood:webhood:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-31218"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Webhood (\u003c= 0.9.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve","web-security"],"_cs_type":"advisory","_cs_vendors":["Webhood"],"content_html":"\u003cp\u003eCVE-2024-31218 is a critical authentication vulnerability affecting Webhood versions 0.9.0 and earlier. The flaw exists within the application's integration with the PocketBase administrative API. When the application has not been initialized with an administrator account, the administrative API does not enforce authentication, allowing unauthenticated remote attackers to create a new administrator account. By successfully creating an account, an attacker gains full administrative control over the application. This vulnerability is classified as CWE-306 (Missing Authentication for Critical Function) and carries a CVSS 3.1 score of 9.8. Defenders should prioritize upgrading to Webhood 0.9.1 or later.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Webhood instances.\u003c/li\u003e\n\u003cli\u003eAttacker probes for the presence of the administrative API endpoint, typically located at /api/admins.\u003c/li\u003e\n\u003cli\u003eAttacker determines if the application is in an uninitialized state (no admin account configured).\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthorized HTTP POST request to the administrative creation endpoint.\u003c/li\u003e\n\u003cli\u003eThe vulnerable Webhood/PocketBase API processes the request without validating an existing session or administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe application creates a new administrative account based on the attacker's supplied credentials.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created administrative credentials.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative access to the platform for data exfiltration or system modification.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative access to the Webhood application, leading to complete compromise of confidentiality, integrity, and availability. Attackers can leverage this access to steal sensitive data, modify application settings, or perform unauthorized operations within the affected environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Webhood instances to version 0.9.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, restrict access to the /api/admins administrative endpoint using a reverse proxy or firewall rules.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to monitor for POST requests to the /api/admins endpoint, especially those originating from unexpected IP addresses or occurring in high-frequency patterns.\u003c/li\u003e\n\u003cli\u003eReview application logs for the creation of new administrator accounts that do not correlate with authorized deployment or administration activities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T07:03:33Z","date_published":"2026-09-20T07:03:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-31218/","summary":"Webhood versions 0.9.0 and earlier contain a critical authentication bypass vulnerability (CVE-2024-31218) allowing unauthenticated attackers to create an administrative account via the PocketBase API.","title":"CVE-2024-31218 Authentication Bypass in Webhood","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-31218/"}],"language":"en","title":"CraftedSignal Threat Feed - Webhood","version":"https://jsonfeed.org/version/1.1"}