PT-2026-71368 · Upsnap · Upsnap

CVE-2026-49819

·

Published

2026-08-12

·

Updated

2026-08-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UpSnap versions 4.4.1 through 5.3.5
Description An authentication bypass and privilege escalation flaw exists in the pb.HandlerInitSuperuser function, accessible via the POST /api/upsnap/init-superuser endpoint. The system fails to implement authentication, setup tokens, IP allow-lists, or rate limiting, relying only on a check for the totalSuperusers variable. On fresh installations, this allows an unauthenticated network-adjacent attacker to register the initial superuser account and obtain a long-lived JSON Web Token (JWT), which is a compact, URL-safe means of representing claims to be transferred between two parties. This can lead to root remote code execution through the exec.CommandContext function using the wake cmd variable.
Recommendations Update to version 5.4.0.

Exploit

Fix

LPE

RCE

Improper Privilege Management

Missing Authorization

OS Command Injection

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49819
GHSA-W4JR-728F-5JHQ

Affected Products

Upsnap