Remote Code Execution Vulnerability in Signal K Server by Signal K
CVE-2026-55591

5.8MEDIUM

Key Information:

Vendor

Signalk

Vendor
CVE Published:
15 September 2026

What is CVE-2026-55591?

The Signal K Server, a central application for marine environments, is prone to a remote code execution vulnerability that allows attackers to exploit endpoints without adequate validation of input parameters. Specifically, functions such as makeRemoteRequest() can accept tampered host, port, useTLS, and selfsignedcert values, leading to unauthorized access to internal services and sensitive data exfiltration. Additionally, the failure in security configurations means certain endpoints lack authentication, further exacerbating the issue. This vulnerability enables potential internal port scanning and unauthorized HTTP requests to untrusted destinations. The issue has been resolved in version 2.28.0. Users are urged to update their installations promptly to mitigate risks.

Affected Version(s)

signalk-server < 2.28.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.