PT-2026-82380 · Rapid7 · Metasploit Framework
CVSS v4.0
5.1
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Metasploit Framework versions prior to 6.5.2
Description
A logic flaw exists in the JSON-RPC web service interface that can lead to a fail-open condition. If an exception occurs during the
db.check() function and the MSF WS JSON RPC API TOKEN environment variable is not explicitly set, the application resets the msf.auth initialized internal state flag to false. The ApiToken Warden authentication strategy misinterprets this value as an indication that authentication is not required or initialized, granting unauthenticated local access to the JSON-RPC request dispatcher.Recommendations
Update to Metasploit Framework version 6.5.2 or later.
Verify the API-token configuration.
Restrict access to RPC interfaces.
Monitor for unexpected local JSON-RPC activity.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasploit Framework