Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.

Project Subscriptions

Vendors Products
Covenant Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.
Title Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub
First Time appeared Cobbr
Cobbr covenant
Weaknesses CWE-306
CPEs cpe:2.3:a:cobbr:covenant:*:*:*:*:*:*:*:*
Vendors & Products Cobbr
Cobbr covenant
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T17:31:37.704Z

Reserved: 2026-09-16T17:20:10.124Z

Link: CVE-2026-92717

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T18:17:22.540

Modified: 2026-09-16T18:17:22.540

Link: CVE-2026-92717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses