Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-108549: cc-connect up to 1.5.0 lets attackers send commands

CVE-2026-108549 · published today
Summary

The cc-connect software (versions up to 1.5.0) accepts messages on its webhook port without checking who sent them, if a secret key is not set. An attacker who can reach that port can pretend to be an authorized user and tell the server to run commands, such as a shell, on the host machine. Set a webhook secret or upgrade to a version that requires authentication to stop this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
chenhg5 cc-connect <= 1.5.0
Original advisory text
cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit (estimated)
  • Gives an attacker full control (estimated)
Severity
9.2 Critical
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Sources
CVE-2026-108549 · MITRE
Track software like this
Free during beta