CVE-2026-82448
Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
| CWE | CWE-798 |
| Vendor | shinobi systems |
| Product | shinobi |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for shinobi systems shinobi
Be the first to know when new critical vulnerabilities affecting shinobi systems shinobi are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Shinobi Systems / Shinobi
0 < 5a76c74f3977661ff3f9fd55a260db352c0b19c0
References
gitlab.com: https://gitlab.com/Shinobi-Systems/Shinobi/-/merge_requests/554 gitlab.com: https://gitlab.com/Shinobi-Systems/Shinobi/-/commit/5a76c74f3977661ff3f9fd55a260db352c0b19c0 gitlab.com: https://gitlab.com/Shinobi-Systems/Shinobi gitlab.com: https://gitlab.com/Shinobi-Systems/Shinobi/-/blob/f04e685b8bd4c6190fcd62993131b86a76c2b806/libs/childNode/utils.js vulncheck.com: https://www.vulncheck.com/advisories/shinobi-before-commit-5a76c74f-arbitrary-database-query-execution-via-hardcoded-child-node-key
Credits
🔍 Sadık Ertürk