LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-82448

Published
CVSS9.8
Severitycritical
WeaknessCWE-798
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-82448

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-82448.