CRITICALVulnerability
CVE-2026-85695
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
Properties
- severity
- CRITICAL
- score
- 9.4
- cve_id
- CVE-2026-85695
- signal_observed_at
- 2026-09-16T13:31:01+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
- published_at
- 2026-09-04T15:17:47.690
- last_modified
- 2026-09-10T15:53:23.707
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Missing Authentication for Critical Function
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph