Authentication Bypass in CrossWatch Synchronization Engine
CVE-2026-53497

5.3MEDIUM

Key Information:

Vendor

Cenodude

Vendor
CVE Published:
21 August 2026

What is CVE-2026-53497?

The CrossWatch Synchronization Engine prior to version 0.9.21 is vulnerable to an authentication bypass that allows unauthorized users to access the GET /api/app-auth/status endpoint. This endpoint returns sensitive session metadata, including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry timestamps. As a result, an unauthenticated network attacker can exploit this vulnerability to enumerate metadata of all active sessions without needing any credentials, raising significant security concerns. Users are advised to upgrade to version 0.9.21 or later to mitigate this risk.

Affected Version(s)

CrossWatch < 0.9.21

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.