Unauthorized Access in ShellHub Centralized SSH Gateway
CVE-2026-44424

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44424?

The ShellHub Centralized SSH Gateway exhibits a critical flaw where authenticated users can access sensitive device metadata due to a lack of proper namespace verification. Specifically, prior to version 0.24.2, the API endpoint GET /api/devices/:uid returns full device objects for any authenticated caller without ensuring that the device belongs to the caller's tenant. As a result, any user with valid authentication credentials could potentially exploit this vulnerability to read device metadata across different namespaces, leading to unauthorized access and privacy breaches. The issue has been addressed in version 0.24.2.

Affected Version(s)

shellhub < 0.24.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.