Cross-Site WebSocket Hijacking Bypass in MeshCentral by Ylianst
CVE-2026-66420

8.6HIGH

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-66420?

MeshCentral version 1.1.21 is susceptible to a cross-site WebSocket hijacking protection bypass. This vulnerability enables unauthenticated attackers to exploit an unconditional early return in the CheckWebServerOriginName() function within webserver.js while using self-signed certificates. Through this exploitation, attackers can initiate cross-origin WebSocket connections to multiple endpoints, sending specially crafted commands that can exfiltrate session keys utilized in signing session cookies. This may allow the attackers to forge session tokens impersonating legitimate users, granting them complete remote control over devices managed by the MeshCentral instance.

Affected Version(s)

openclaw-dashboard 1.1.21

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ashish Kunwar (@D0rkerDevil)
.