PT-2026-56541 · Unknown · Midscene Bridge Server

·

CVE-2026-59804

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Midscene Bridge Server versions prior to 1.10.4
Description Missing authentication and Cross-Origin Resource Sharing (CORS) misconfiguration allow unauthenticated remote attackers to hijack active bridge sessions. This occurs because the local Socket.IO server does not perform Origin header validation and does not require an authentication token, enabling a cross-origin WebSocket connection. An attacker can connect via any web page visited by the victim to seize the single-client slot, intercept and inject automation commands, or exfiltrate command-payload data. Additionally, the server can be unconditionally terminated by providing the MIDSCENE BRIDGE SIGNAL KILL query parameter.
Recommendations Update to the version containing commit 86f4118.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59804

Affected Products

Midscene Bridge Server