Logic Vulnerability in Metasploit Framework's JSON-RPC Web Service Interface
CVE-2026-16895

5.1MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
27 August 2026

What is CVE-2026-16895?

A critical flaw exists in the JSON-RPC web service interface of the Metasploit Framework, where a fail-open condition can occur. If the application encounters an exception during a database health check and the required API token is not set, it inadvertently resets the internal authentication state. This misconfiguration allows unauthorized users to gain local access to functionalities intended for authenticated users, exposing systems to potential misuse or security breaches. Administrators must ensure that the API token is properly configured to prevent unauthorized access.

Affected Version(s)

Metasploit-framework 0 < 6.5.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaime Cavero
.