Missing Authentication Vulnerability in cc-connect for MAX Platform Adapter by Chenhg5
CVE-2026-108549

9.2CRITICAL

Key Information:

Vendor

Chenhg5

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108549?

The cc-connect software, specifically version 1.5.0, is susceptible to a missing authentication flaw within the MAX platform adapter's webhook listener. This vulnerability allows remote attackers to bypass authentication mechanisms when no webhook secret is established. As a result, attackers can send forged updates mimicking allowed or administrative user IDs, enabling them to execute privileged commands on the host system via the designated webhook listener on port 8080. This poses significant security risks, as unauthorized users could exploit this weakness to gain elevated access to the server.

Affected Version(s)

cc-connect 0 <= 1.5.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.