SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90507

MEDIUM · CVSS 6.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The vulnerability in the WARP-Clash-API's Subscription Handler allows for improper access controls through manipulation of the `key` argument in the `get_surge_subscription` function, which can be exploited remotely. As the exploit is publicly available and affects unsupported products, organizations still using these versions should prioritize remediation to mitigate potential unauthorized access. Immediate action is recommended for those relying on this API to ensure the security of their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90507
Severity
MEDIUM
CVSS
6.3
EPSS
N/A

Original NVD Description

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.