Information Exposure in Flame through 2.4.0 by Pawel Malak
CVE-2026-100418

6.9MEDIUM

Key Information:

Vendor

Pawelmalak

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100418?

An information exposure vulnerability exists in Flame version 2.4.0 due to the unauthenticated GET /api/config endpoint. This flaw allows attackers to access the full configuration object, including sensitive components such as the weather API key and internal operational settings, without authentication. By sending a single unauthorized request, malicious actors can exploit this vulnerability to consume service quotas or disclose critical configuration details. Proper authentication measures are essential to secure sensitive information.

Affected Version(s)

flame 0 <= 2.4.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lazizbek Djurayev (Haad TC)
.