Telemetry Configuration Exposure in AnyCable Realtime Server
CVE-2026-63406

5.9MEDIUM

Key Information:

Vendor

Anycable

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-63406?

The telemetry subsystem in AnyCable prior to version 1.6.15 features a hardcoded public authentication token that, while used for tracking purposes, could lead to potential configuration exposure. The system reads sensitive information from the configuration file and command-line arguments, which includes values passed through critical parameters. Despite the telemetry data not revealing raw credentials directly, the method of generating a fingerprint from sensitive configurations can compromise the confidentiality of the setup. It's important to upgrade to version 1.6.15 to mitigate this vulnerability and enhance security.

Affected Version(s)

anycable < 1.6.15

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.