Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher. | |
| Title | Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-27T13:09:40.173Z
Reserved: 2026-07-24T05:29:02.405Z
Link: CVE-2026-16895
Updated: 2026-08-27T13:09:37.142Z
Status : Awaiting Analysis
Published: 2026-08-27T04:16:41.530
Modified: 2026-08-28T21:17:10.720
Link: CVE-2026-16895
No data.
OpenCVE Enrichment
Updated: 2026-08-27T05:30:07Z