


Perceptive Security
SOC/SIEM Consultancy

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploit…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 21:05:50
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
Spikster, through commit e1cdf8c, contains a critical missing authentication vulnerability affecting all API routes. The CipiAuth middleware is registered but never applied to any route in the API routing configuration, leaving approximately 50 API endpoints completely unprotected. Unauthenticated remote attackers can exploit this flaw to enumerate and provision servers, reset root passwords, read and write arbitrary files on the host system, and create database users. The vulnerability requires no credentials or special access, making it trivially exploitable by any remote attacker. The impact is severe as it grants near-complete control over managed servers and hosted infrastructure. A GitHub issue and VulnCheck advisory have been published detailing the flaw.
Technical details
Mitigation steps:
Affected products:
Spikster
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67594
https://github.com/yolanmees/Spikster/issues/24
https://www.vulncheck.com/advisories/spikster-missing-authentication-via-api-route-group
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
