Medium severity5.3NVD Advisory· Published Sep 15, 2026
CVE-2026-91997
CVE-2026-91997
Description
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.
Affected products
2- Range: <=2.3.7
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.