Authentication Bypass in OpenSave by Liquid.co Allows Impersonation of Devices
CVE-2026-103397

6.3MEDIUM

Key Information:

Vendor

Liquid-co

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103397?

The OpenSave application, prior to version 2.4.0-beta.1, contains a vulnerability where sender identity validation in WAN relay requests is insufficient. This allows unpaired room members to impersonate legitimate paired devices by manipulating the RelayMessage's From field. Malicious actors who possess the room code can gain access, retrieve identifiers of paired peers from announcements, and issue forged requests that compromise protected sync routes, enabling unauthorized access to sensitive data, including save states, snapshots, and file operations.

Affected Version(s)

OpenSave 0 < 2.4.0-beta.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mansurmavlankulov
.