Unauthenticated Key Exposure in Keploy Agent Control-Plane
CVE-2026-82641
8.8HIGH
What is CVE-2026-82641?
Versions 3.1.0 through 3.6.25 of Keploy are vulnerable as the control-plane HTTP server is bound to all interfaces without authentication. This significant flaw allows attackers to access critical endpoints, such as /agent/pcap/keylog, which exposes TLS session keys and traffic data. Additionally, the /agent/stop and /agent/storemocks endpoints can be exploited by attackers to manipulate recording sessions. Organizations using these versions should apply the necessary patches promptly to mitigate risks associated with unauthorized data access and potential manipulation of security parameters.
Affected Version(s)
keploy 3.1.0 <= 3.6.25
