PT-2026-99120 · Unknown · Scbe-Aethermoore

CVE-2026-57443

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SCBE-AETHERMOORE versions 4.0.2 through 4.2.0
Description The AetherBrowser API server (scripts/aetherbrowser/api server.py) exposes the POST /api/ops/check-email endpoint without authentication. A remote attacker can call this endpoint to trigger the execution of the email reader.py subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP. The server then returns email metadata, including the sender, subject, and a body snippet, in the JSON response. By default, the server binds to 0.0.0.0:8100 and uses a Cross-Origin Resource Sharing (CORS) configuration that allows all origins, making it accessible from any network or browser origin.
Recommendations Update to version 4.2.1. As a temporary mitigation, restrict access to the POST /api/ops/check-email endpoint or disable the email reader.py subprocess until the update is applied.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57443
GHSA-Q986-4X7X-GX39

Affected Products

Scbe-Aethermoore