Vulnerability Description
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/mysteriumnetwork/node/
- https://github.com/mysteriumnetwork/node/commit/bc099fcaff59fee9c8a8f8e07ffff5b3
- https://github.com/sch8ill/CVE-2026-31309
- https://github.com/sch8ill/CVE-2026-31309
FAQ
What is CVE-2026-31309?
CVE-2026-31309 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and...
How severe is CVE-2026-31309?
CVE-2026-31309 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-31309?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.