Cyber & AI intelligence
Wasteland.
Briefs indexed2957
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-103244 2026-10-01

CVE-2026-103244: Unauthenticated Admin Takeover in ground-station via setup.restore

"An authentication bypass in ground-station versions before 0.8.0 lets unauthenticated attackers run arbitrary SQL during first-run setup and take full administrative control of the application."

An authentication bypass in ground-station versions before 0.8.0 lets unauthenticated attackers run arbitrary SQL during first-run setup and take full administrative control of the application.

What Is It

CVE-2026-103244 is an authentication bypass in the setup.restore command of sgoudelis' ground-station. NVD classifies it as CWE-306 (Missing Authentication for Critical Function). While the application is in first-run setup mode, an unauthenticated attacker can call setup.restore over Socket.IO and run arbitrary SQL. According to the advisory, attackers can use this to create admin users and forged session tokens. They can then log in as an administrator without credentials, which gives them complete control of the application.

The CVE was published to NVD on 2026-10-01 and is currently in "Received" status. VulnCheck is the reporting source.

Why It Matters

The attack works over the network, has low complexity, and needs no privileges or user interaction. Confidentiality, integrity and availability impacts are all rated High. Because the attacker can run arbitrary SQL and create admin users, a successful attack goes beyond bypassing a login and amounts to full takeover. The exposure window is first-run setup mode, so instances that are newly deployed or not yet configured are most at risk.

This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The supplied data does not confirm any active exploitation.

What's Vulnerable

The NVD record lists no CPEs yet.

Patch Status

The affected range ends below 0.8.0, which means 0.8.0 is the first version outside the vulnerable range. The NVD references include an upstream fix commit and a GitHub Security Advisory (GHSA-3mqj-q84c-crjq).

Recommended actions: - Upgrade ground-station to 0.8.0 or later. - Until you upgrade, do not leave instances in first-run setup mode where untrusted networks can reach them.

No CISA KEV required action or due date applies.

Sources