PT-2026-97529 · Klever-Go · Klever-Go

CVE-2026-86064

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description An unauthenticated remote client can connect to the default-open GET /log WebSocket endpoint. The server parses the first client message as a logger Profile and applies it process-wide using the Profile.Apply() function. This allows an attacker to change global log levels and formatting options, such as setting the log level to *:NONE to suppress normal logs or *:TRACE to increase verbosity. Additionally, the connection is registered as a log observer, enabling the attacker to access live operational process logs. This flaw impacts operational integrity and confidentiality by distorting operator visibility and exposing internal information.
Recommendations Update to version 1.7.20. As a temporary workaround, remove /log from the default open route set in config/node/api.yaml or restrict access to the GET /log endpoint to localhost only.

Exploit

Fix

Missing Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86064
GHSA-9V8P-FRVJ-2PCM

Affected Products

Klever-Go