PT-2026-38314 · Shellhub · Shellhub

CVE-2026-44424

·

Published

2026-05-06

·

Updated

2026-07-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ShellHub versions prior to 0.24.2
Description An issue exists where the endpoint "/api/devices/:uid" returns the full device object to any authenticated user without verifying if the device belongs to the caller's namespace (tenant). An authenticated user possessing a JWT or API Key who knows or can guess a device uid can read device metadata from other namespaces. This leads to cross-tenant disclosure of information such as hostnames, MAC addresses, OS fingerprints, public SSH keys, namespace names, last-seen timestamps, and remote addresses, which can be used for namespace enumeration and device inventory reconnaissance.
Recommendations Update to version 0.24.2.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44424
GHSA-J72X-XFWG-783F
GO-2026-5453
OPENSUSE-SU-2026:21483-1

Affected Products

Shellhub