PT-2026-95514 · Anycable · Anycable
CVE-2026-63406
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnyCable versions prior to 1.6.15
Description
The telemetry subsystem contains a hardcoded authentication token in
telemetry/config.go used to authenticate to https://telemetry.anycable.io. Additionally, the clusterFingerprint() function in telemetry/telemetry.go processes the full configuration file and raw command-line arguments via anycableCLIArgs(), including sensitive values passed through --secret, --jwt secret, and --http rpc secret. These raw inputs are passed to the generateDigest() function to create a hexadecimal fingerprint sent as telemetry. Because the authentication token is public, an attacker capable of DNS hijacking or network interception could potentially intercept the telemetry payload containing data derived from operator credentials.Recommendations
Update to version 1.6.15.
As a temporary mitigation, avoid using the
--secret, --jwt secret, and --http rpc secret flags when starting the server until the update is applied.Exploit
Fix
Cleartext Storage of Sensitive Information
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anycable