PT-2026-66575 · Spikster · Spikster
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spikster versions prior to commit e1cdf8c
Description
A missing authentication flaw allows unauthenticated remote attackers to access all API routes. This occurs because the
CipiAuth middleware is registered but not applied to any route within the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root passwords, read and write arbitrary files on the host, and create database users.Recommendations
Update Spikster to a version including commit e1cdf8c or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spikster