top of page
perceptive_background_267k.jpg

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploit…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 21:05:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

Spikster, through commit e1cdf8c, contains a critical missing authentication vulnerability affecting all API routes. The CipiAuth middleware is registered but never applied to any route in the API routing configuration, leaving approximately 50 API endpoints completely unprotected. Unauthenticated remote attackers can exploit this flaw to enumerate and provision servers, reset root passwords, read and write arbitrary files on the host system, and create database users. The vulnerability requires no credentials or special access, making it trivially exploitable by any remote attacker. The impact is severe as it grants near-complete control over managed servers and hosted infrastructure. A GitHub issue and VulnCheck advisory have been published detailing the flaw.

Technical details

Mitigation steps:

Affected products:

Spikster

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page