Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-82448: Shinobi lets unauthenticated users run database queries
CVE-2026-82448 · published 5 days ago
Summary
Versions of Shinobi released before the 5a76c74f code change contain a built‑in password that anyone can use to connect to the part of the system that talks to the database. An attacker who can reach that network port could issue commands to read or change user accounts and camera settings. Update Shinobi to the latest release, which removes the hard‑coded password, and limit network access to that port.
What to do
- Update shinobi systems shinobi to version 5a76c74f3977661ff3f9fd55a260db352c0b19c0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| shinobi systems | shinobi | < 5a76c74f3977661ff3f9fd55a260db352c0b19c0 |
Original advisory text
Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
References
- https://gitlab.com/Shinobi-Systems/Shinobi
- https://gitlab.com/Shinobi-Systems/Shinobi/-/blob/f04e685b8bd4c6190fcd62993131b8...
- https://gitlab.com/Shinobi-Systems/Shinobi/-/commit/5a76c74f3977661ff3f9fd55a260...
- https://gitlab.com/Shinobi-Systems/Shinobi/-/merge_requests/554
- https://www.vulncheck.com/advisories/shinobi-before-commit-5a76c74f-arbitrary-da...
- https://nvd.nist.gov/vuln/detail/CVE-2026-82448 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82448... Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta