Logic Vulnerability in Metasploit Framework's JSON-RPC Web Service Interface
CVE-2026-16895
5.1MEDIUM
What is CVE-2026-16895?
A critical flaw exists in the JSON-RPC web service interface of the Metasploit Framework, where a fail-open condition can occur. If the application encounters an exception during a database health check and the required API token is not set, it inadvertently resets the internal authentication state. This misconfiguration allows unauthorized users to gain local access to functionalities intended for authenticated users, exposing systems to potential misuse or security breaches. Administrators must ensure that the API token is properly configured to prevent unauthorized access.
Affected Version(s)
Metasploit-framework 0 < 6.5.2
