OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92717

CRITICAL · CVSS 9.1 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Covenant through version 0.6 is vulnerable due to the lack of an Authorize attribute on the CovenantHub SignalR hub, enabling unauthenticated users to invoke the CreateHttpListener method and obtain a signed JWT token. This token can be exploited by attackers to gain unauthorized access to the operator API, compromising sensitive data such as credentials, binaries, and the operator roster. Organizations using this version should prioritize immediate remediation to prevent potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92717
Severity
CRITICAL
CVSS
9.1
EPSS
0.50%

Original NVD Description

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.