Authentication Bypass in CrossWatch Synchronization Engine
CVE-2026-53497
5.3MEDIUM
What is CVE-2026-53497?
The CrossWatch Synchronization Engine prior to version 0.9.21 is vulnerable to an authentication bypass that allows unauthorized users to access the GET /api/app-auth/status endpoint. This endpoint returns sensitive session metadata, including originating IP addresses, User-Agent strings, internal session IDs, and creation/expiry timestamps. As a result, an unauthenticated network attacker can exploit this vulnerability to enumerate metadata of all active sessions without needing any credentials, raising significant security concerns. Users are advised to upgrade to version 0.9.21 or later to mitigate this risk.
Affected Version(s)
CrossWatch < 0.9.21
