CVE Feed

    Dashboard / CVE / CVE-2026-82448

    CVE-2026-82448

    Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

    Published:Aug 29, 2026
    Last Modified:Aug 31, 2026
    EPS:Aug 29, 2026
    EPSS Score:0.00407
    CVSS Score:9.8

    Affected Products

    Vendor
    Shinobi Systems
    Product
    Shinobi

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High