PT-2026-82067 · Tarsweb · Tarsweb

·

CVE-2026-80349

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TarsWeb versions prior to 3.0.16
Description TarsWeb incorrectly determines if a request originates from a trusted local caller by relying on a client-controlled header. The app.js file enables the Koa proxy option without specifying trusted upstream proxies or limiting forwarded hops, causing the reported request address to be taken from the X-Forwarded-For header. In midware/ssoMidware.js, a logic error in a branch handling both the ignored-path list and the ignoreIps allowlist (which includes the loopback address) allows the system to assign an account identity based on the uid query parameter without validating tickets, cookies, or passwords. An attacker can forge the X-Forwarded-For header to mimic the loopback address and provide a uid to gain unauthorized access to any account, including administrators. This grants access to routes for user and role administration, service configuration, and package upload and deployment.
Recommendations Update TarsWeb to version 3.0.16.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80349

Affected Products

Tarsweb