Telemetry Configuration Exposure in AnyCable Realtime Server
CVE-2026-63406
5.9MEDIUM
What is CVE-2026-63406?
The telemetry subsystem in AnyCable prior to version 1.6.15 features a hardcoded public authentication token that, while used for tracking purposes, could lead to potential configuration exposure. The system reads sensitive information from the configuration file and command-line arguments, which includes values passed through critical parameters. Despite the telemetry data not revealing raw credentials directly, the method of generating a fingerprint from sensitive configurations can compromise the confidentiality of the setup. It's important to upgrade to version 1.6.15 to mitigate this vulnerability and enhance security.
Affected Version(s)
anycable < 1.6.15
