Unauthenticated Key Exposure in Keploy Agent Control-Plane
CVE-2026-82641

8.8HIGH

Key Information:

Vendor

Keploy

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82641?

Versions 3.1.0 through 3.6.25 of Keploy are vulnerable as the control-plane HTTP server is bound to all interfaces without authentication. This significant flaw allows attackers to access critical endpoints, such as /agent/pcap/keylog, which exposes TLS session keys and traffic data. Additionally, the /agent/stop and /agent/storemocks endpoints can be exploited by attackers to manipulate recording sessions. Organizations using these versions should apply the necessary patches promptly to mitigate risks associated with unauthorized data access and potential manipulation of security parameters.

Affected Version(s)

keploy 3.1.0 <= 3.6.25

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.