Cross-Site WebSocket Hijacking Bypass in MeshCentral by Ylianst
CVE-2026-66420
8.6HIGH
What is CVE-2026-66420?
MeshCentral version 1.1.21 is susceptible to a cross-site WebSocket hijacking protection bypass. This vulnerability enables unauthenticated attackers to exploit an unconditional early return in the CheckWebServerOriginName() function within webserver.js while using self-signed certificates. Through this exploitation, attackers can initiate cross-origin WebSocket connections to multiple endpoints, sending specially crafted commands that can exfiltrate session keys utilized in signing session cookies. This may allow the attackers to forge session tokens impersonating legitimate users, granting them complete remote control over devices managed by the MeshCentral instance.
Affected Version(s)
openclaw-dashboard 1.1.21
