Unauthorized Access in ShellHub Centralized SSH Gateway
CVE-2026-44424
6.5MEDIUM
What is CVE-2026-44424?
The ShellHub Centralized SSH Gateway exhibits a critical flaw where authenticated users can access sensitive device metadata due to a lack of proper namespace verification. Specifically, prior to version 0.24.2, the API endpoint GET /api/devices/:uid returns full device objects for any authenticated caller without ensuring that the device belongs to the caller's tenant. As a result, any user with valid authentication credentials could potentially exploit this vulnerability to read device metadata across different namespaces, leading to unauthorized access and privacy breaches. The issue has been addressed in version 0.24.2.
Affected Version(s)
shellhub < 0.24.2
