High severity8.6NVD Advisory· Published Apr 27, 2021· Updated Jun 17, 2026
CVE-2021-29441
CVE-2021-29441
Description
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.alibaba.nacos:nacos-commonMaven | < 1.4.1 | 1.4.1 |
Affected products
3- alibaba/nacosv5Range: < 1.4.1
Patches
Vulnerability mechanics
References
4- github.com/alibaba/nacos/pull/4703nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-36hp-jr8h-556fnvdExploitThird Party AdvisoryADVISORY
- github.com/alibaba/nacos/issues/4701nvdExploitThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-29441ghsaADVISORY
News mentions
9- The Signs Were There: What the First Autonomous Ransomware Case ConfirmsTrend Micro Research · Jul 24, 2026
- Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesThe Hacker News · Jul 10, 2026
- AI Agent Pulls Off a Ransomware Attack Without Human HelpGovInfoSecurity · Jul 6, 2026
- Researchers Claim First Fully Agentic Ransomware: JadePufferInfosecurity Magazine · Jul 6, 2026
- JadePuffer ransomware used AI agent to automate entire attackBleepingComputer · Jul 4, 2026
- Agentic AI Used to Conduct Ransomware Attack via LangflowSecurityWeek · Jul 3, 2026
- Smooth AI criminal drives 'first' end-to-end agentic ransomware attackThe Register Security · Jul 2, 2026
- Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API KeysCyber Security News · Jul 2, 2026
- AI Agent Exploits Langflow RCE to Automate Database Ransomware AttackThe Hacker News · Jul 2, 2026