Authentication Bypass Vulnerability in TarsWeb by TarsCloud
CVE-2026-80349
What is CVE-2026-80349?
The vulnerability in TarsWeb occurs when the application relies on a client-controlled header to determine if a request is from a trusted source. TarsWeb's configuration improperly allows requests to bypass authentication checks by exploiting the X-Forwarded-For header and uid query parameter. Forged requests can impersonate any user, including administrators, granting access to sensitive routes such as user and role administration, service configuration, and system deployment without any required credentials. This critical oversight arises from two branches in the middleware handling request processing that fail to validate incoming requests properly, enabling attackers to gain unauthorized access to critical functionality within the TarsWeb environment.
Affected Version(s)
TarsWeb 0 <= 3.0.14
