CVE-2026-29023: CWE-798 Use of Hard-coded Credentials in KeygraphHQ Shannon
Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s configured upstream provider API credentials, resulting in unauthorized API usage and potential disclosure of proxied request and response data. This vulnerability's general exploitability has been mitigated with the introduction of commit 023cc95.
AI Analysis
Technical Summary
CVE-2026-29023 describes a vulnerability in KeygraphHQ Shannon where a hard-coded API key is embedded in the router configuration. If the router component is enabled and accessible over the network, attackers can authenticate using this known static key. This enables them to proxy requests through the Shannon instance, leveraging the victim’s upstream provider API credentials without authorization. The vulnerability is classified under CWE-798 (Use of Hard-coded Credentials). Although the affected version is 0, a mitigation commit (023cc95) has been introduced to reduce exploitability.
Potential Impact
An attacker who can reach the router port can authenticate with the hard-coded key, allowing unauthorized proxying of API requests. This can result in unauthorized API usage and potential exposure of sensitive data contained in proxied requests and responses. The CVSS 4.0 score of 6.9 (medium severity) reflects network attack vector, low complexity, no privileges or user interaction required, and low to low impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix has been introduced in commit 023cc95 that mitigates the general exploitability of this vulnerability. Users should update to a version that includes this commit or apply the patch if available. Since no official patch link is provided, users must consult KeygraphHQ for the updated version or patch. Until then, disabling or restricting access to the router component can reduce exposure.
CVE-2026-29023: CWE-798 Use of Hard-coded Credentials in KeygraphHQ Shannon
Description
Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance using the victim’s configured upstream provider API credentials, resulting in unauthorized API usage and potential disclosure of proxied request and response data. This vulnerability's general exploitability has been mitigated with the introduction of commit 023cc95.
CVSS v4.0
Score 6.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-29023 describes a vulnerability in KeygraphHQ Shannon where a hard-coded API key is embedded in the router configuration. If the router component is enabled and accessible over the network, attackers can authenticate using this known static key. This enables them to proxy requests through the Shannon instance, leveraging the victim’s upstream provider API credentials without authorization. The vulnerability is classified under CWE-798 (Use of Hard-coded Credentials). Although the affected version is 0, a mitigation commit (023cc95) has been introduced to reduce exploitability.
Potential Impact
An attacker who can reach the router port can authenticate with the hard-coded key, allowing unauthorized proxying of API requests. This can result in unauthorized API usage and potential exposure of sensitive data contained in proxied requests and responses. The CVSS 4.0 score of 6.9 (medium severity) reflects network attack vector, low complexity, no privileges or user interaction required, and low to low impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix has been introduced in commit 023cc95 that mitigates the general exploitability of this vulnerability. Users should update to a version that includes this commit or apply the patch if available. Since no official patch link is provided, users must consult KeygraphHQ for the updated version or patch. Until then, disabling or restricting access to the router component can reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-03-03T17:24:13.913Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 69af0b9eea502d3aa8af25bb
Added to database: 03/09/2026, 18:04:14 UTC
Last enriched: 07/15/2026, 10:50:16 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 235
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.