๐Ÿ” CVE Alert

CVE-2026-92717

CRITICAL 9.1

Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.

CWE CWE-306
Vendor cobbr
Product covenant
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for cobbr covenant

Be the first to know when new critical vulnerabilities affecting cobbr covenant are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

cobbr / Covenant
0 โ‰ค 0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cobbr/Covenant/issues/406 github.com: https://github.com/cobbr/Covenant github.com: https://github.com/cobbr/Covenant/blob/v0.6/Covenant/Hubs/CovenantHub.cs#L28-L33 github.com: https://github.com/cobbr/Covenant/blob/v0.6/Covenant/Core/CovenantService.cs#L3958-L3975 vulncheck.com: https://www.vulncheck.com/advisories/covenant-through-0.6-missing-authentication-on-the-covenanthub-signalr-hub

Credits

๐Ÿ” George Chen