CVE-2026-48117: CWE-287: Improper Authentication in fduflyer DroneAware-Node-Releases
DroneAware's centralized server was vulnerable to an account pre-hijacking flaw allowing attackers to register accounts with victim emails and attacker-chosen passwords before the victim activated their account. When the victim later activated the account, the attacker-set password remained valid, enabling silent account takeover without notification. The issue was fixed server-side on 2025-05-20, requiring no user action. Node binaries and self-hosted detection nodes are unaffected. No client-side mitigations or workarounds are needed.
AI Analysis
Technical Summary
CVE-2026-48117 describes an improper authentication vulnerability (CWE-287) in the DroneAware centralized server. The flaw allowed an attacker to pre-register an account using a victim's email with an attacker-controlled password before the victim completed account activation. Upon victim activation via email verification or Google SSO, the attacker-set password remained valid, enabling persistent unauthorized access without alerting the victim. The vulnerability was addressed with a server-side fix deployed on 2025-05-20. Self-hosted nodes and binaries are not affected, and no client-side remediation is applicable.
Potential Impact
Successful exploitation allows an attacker to silently and persistently take over a victim's DroneAware account by pre-registering it with the victim's email and attacker-controlled password. This results in unauthorized access with high confidentiality and integrity impact, but no availability impact. The victim receives no notification of the compromise. The vulnerability affects only the centralized DroneAware server and not self-hosted nodes.
Mitigation Recommendations
The vulnerability was fixed by the vendor with a server-side patch deployed on 2025-05-20. No user action or client-side mitigation is required. There are no workarounds. Users and administrators should ensure they are using the official DroneAware service where the fix is applied.
CVE-2026-48117: CWE-287: Improper Authentication in fduflyer DroneAware-Node-Releases
Description
DroneAware's centralized server was vulnerable to an account pre-hijacking flaw allowing attackers to register accounts with victim emails and attacker-chosen passwords before the victim activated their account. When the victim later activated the account, the attacker-set password remained valid, enabling silent account takeover without notification. The issue was fixed server-side on 2025-05-20, requiring no user action. Node binaries and self-hosted detection nodes are unaffected. No client-side mitigations or workarounds are needed.
CVSS v3.1
Score 6.8medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-48117 describes an improper authentication vulnerability (CWE-287) in the DroneAware centralized server. The flaw allowed an attacker to pre-register an account using a victim's email with an attacker-controlled password before the victim completed account activation. Upon victim activation via email verification or Google SSO, the attacker-set password remained valid, enabling persistent unauthorized access without alerting the victim. The vulnerability was addressed with a server-side fix deployed on 2025-05-20. Self-hosted nodes and binaries are not affected, and no client-side remediation is applicable.
Potential Impact
Successful exploitation allows an attacker to silently and persistently take over a victim's DroneAware account by pre-registering it with the victim's email and attacker-controlled password. This results in unauthorized access with high confidentiality and integrity impact, but no availability impact. The victim receives no notification of the compromise. The vulnerability affects only the centralized DroneAware server and not self-hosted nodes.
Mitigation Recommendations
The vulnerability was fixed by the vendor with a server-side patch deployed on 2025-05-20. No user action or client-side mitigation is required. There are no workarounds. Users and administrators should ensure they are using the official DroneAware service where the fix is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T18:46:58.290Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a32b82c9f87a2db090fd5f0
Added to database: 06/17/2026, 15:07:24 UTC
Last enriched: 06/24/2026, 16:29:58 UTC
Last updated: 08/01/2026, 19:18:00 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.