Missing Authentication Vulnerability in cc-connect for MAX Platform Adapter by Chenhg5
CVE-2026-108549
9.2CRITICAL
What is CVE-2026-108549?
The cc-connect software, specifically version 1.5.0, is susceptible to a missing authentication flaw within the MAX platform adapter's webhook listener. This vulnerability allows remote attackers to bypass authentication mechanisms when no webhook secret is established. As a result, attackers can send forged updates mimicking allowed or administrative user IDs, enabling them to execute privileged commands on the host system via the designated webhook listener on port 8080. This poses significant security risks, as unauthorized users could exploit this weakness to gain elevated access to the server.
Affected Version(s)
cc-connect 0 <= 1.5.0
