Missing Authentication in WARP-Clash-API by vvbbnn00
CVE-2026-90504
Key Information:
- Vendor
Vvbbnn00
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90504?
A significant vulnerability exists within the WARP-Clash-API by vvbbnn00, specifically related to the function authorized. This issue arises from improper handling of the SECRET_KEY argument, which results in missing authentication and allows for unauthorized access. This vulnerability can be exploited remotely, posing a risk to users of this API, especially those using versions that are no longer supported. As continuous delivery practices are adopted by this product, it poses a challenge in identifying updated versions or specific patches.
Affected Version(s)
WARP-Clash-API c7bf2360073959861219b422e51ae86411051b46
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
