PT-2026-93880 · Cobbr+1 · Covenant
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Covenant versions prior to 0.7
Description
The software registers the 'CovenantHub' SignalR hub without an Authorize attribute. This allows unauthenticated users to invoke the
CreateHttpListener() function and obtain a signed JWT (JSON Web Token), which is a compact, URL-safe means of representing claims to be transferred between two parties. With this token, an attacker can authenticate against the operator API to access grunts, credentials, binaries, events, and the operator roster.Recommendations
Update Covenant to version 0.7 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Covenant