PT-2026-95514 · Anycable · Anycable

CVE-2026-63406

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AnyCable versions prior to 1.6.15
Description The telemetry subsystem contains a hardcoded authentication token in telemetry/config.go used to authenticate to https://telemetry.anycable.io. Additionally, the clusterFingerprint() function in telemetry/telemetry.go processes the full configuration file and raw command-line arguments via anycableCLIArgs(), including sensitive values passed through --secret, --jwt secret, and --http rpc secret. These raw inputs are passed to the generateDigest() function to create a hexadecimal fingerprint sent as telemetry. Because the authentication token is public, an attacker capable of DNS hijacking or network interception could potentially intercept the telemetry payload containing data derived from operator credentials.
Recommendations Update to version 1.6.15. As a temporary mitigation, avoid using the --secret, --jwt secret, and --http rpc secret flags when starting the server until the update is applied.

Exploit

Fix

Cleartext Storage of Sensitive Information

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63406
GHSA-W72W-9QMJ-C9QM
GO-2026-6529

Affected Products

Anycable