Missing Authentication on CovenantHub SignalR Hub in Covenant by Cobbr
CVE-2026-92717

9.3CRITICAL

Key Information:

Vendor

Cobbr

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92717?

The Covenant software, up to version 0.6, exposes a significant security vulnerability where the CovenantHub SignalR hub lacks an Authorize attribute. This deficiency permits unauthorized callers to invoke the CreateHttpListener method, obtaining a signed JWT token. This token can be manipulated by attackers to authenticate against the entire operator API, enabling access to sensitive information, such as grunts, credentials, binaries, events, and the operator roster. Ensuring proper authentication measures are in place is critical to mitigate potential exploits.

Affected Version(s)

Covenant 0 <= 0.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.