PT-2026-71368 · Upsnap · Upsnap
CVE-2026-49819
·
Published
2026-08-12
·
Updated
2026-08-13
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UpSnap versions 4.4.1 through 5.3.5
Description
An authentication bypass and privilege escalation flaw exists in the
pb.HandlerInitSuperuser function, accessible via the POST /api/upsnap/init-superuser endpoint. The system fails to implement authentication, setup tokens, IP allow-lists, or rate limiting, relying only on a check for the totalSuperusers variable. On fresh installations, this allows an unauthenticated network-adjacent attacker to register the initial superuser account and obtain a long-lived JSON Web Token (JWT), which is a compact, URL-safe means of representing claims to be transferred between two parties. This can lead to root remote code execution through the exec.CommandContext function using the wake cmd variable.Recommendations
Update to version 5.4.0.
Exploit
Fix
LPE
RCE
Improper Privilege Management
Missing Authorization
OS Command Injection
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Upsnap