Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-31309: Mysterium Node Configuration Hijacking via Unauthenticated Access

CVE-2026-31309 CVE-2026-31309
Summary

An attacker can access and change Mysterium Node settings without a password, potentially taking control of the node. This is a serious issue because it allows an attacker to manipulate the node's behavior. Mysterium Node users should update to version 1.36.0 or later to fix this problem.

Original title
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration ...
Original description
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
Vulnerability type
CWE-862 Missing Authorization
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026