PT-2026-97529 · Klever-Go · Klever-Go
CVE-2026-86064
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
An unauthenticated remote client can connect to the default-open
GET /log WebSocket endpoint. The server parses the first client message as a logger Profile and applies it process-wide using the Profile.Apply() function. This allows an attacker to change global log levels and formatting options, such as setting the log level to *:NONE to suppress normal logs or *:TRACE to increase verbosity. Additionally, the connection is registered as a log observer, enabling the attacker to access live operational process logs. This flaw impacts operational integrity and confidentiality by distorting operator visibility and exposing internal information.Recommendations
Update to version 1.7.20.
As a temporary workaround, remove
/log from the default open route set in config/node/api.yaml or restrict access to the GET /log endpoint to localhost only.Exploit
Fix
Missing Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Klever-Go