Loading market data...
← Back to CVE feed

CVE-2026-103244

CRITICAL CVSS 9.8 View on NVD ↗

Description

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 15:09 UTC