High severity8.1NVD Advisory· Published Oct 10, 2026· Updated Oct 10, 2026
CVE-2026-108549
CVE-2026-108549
Description
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.5.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.