CRITICALVulnerability

CVE-2026-82448

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-82448
signal_observed_at
2026-09-23T22:44:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-29T13:16:38.877
last_modified
2026-09-23T17:17:43.827

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Credentials

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82448 — Ninja Signal Threat Intelligence | Ninja Signal