OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96770

CRITICAL · CVSS 9.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions of s2s-proxy up to 0.2.2 are vulnerable due to improper TLS client certificate verification, allowing attackers to exploit the system using self-signed certificates. This critical vulnerability enables unauthorized access to RPCs permitted by the proxy's configuration and Temporal credentials, posing significant risks to data integrity and confidentiality. Organizations utilizing s2s-proxy should prioritize immediate remediation to safeguard their systems against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96770
Severity
CRITICAL
CVSS
9.3
EPSS
0.25%

Original NVD Description

All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the certificate against the configured CA. An attacker can therefore use a self-signed certificate and key to establish a TLS and yamux connection, then invoke RPCs allowed by the proxy's configuration and Temporal credentials. No certificate or private key trusted by the deployment, and no Temporal credential, is required.