CVE-2026-50194: CWE-288: Authentication Bypass Using an Alternate Path or Channel in SteeltoeOSS Steeltoe.Management.Endpoint
Steeltoe.Management.Endpoint versions 3.2.2, 3.3.0, and 4.1.0 contain an authentication bypass vulnerability when configured to listen on an alternate port. The middleware incorrectly uses the HTTP Host header instead of the actual network socket port to restrict access, allowing potential unauthorized access to management endpoints. Versions 3.4.0 and 4.2.0 address this issue. Mitigations include upgrading to patched versions or applying explicit ASP.NET Core authorization and configuring reverse proxies to validate the Host header.
AI Analysis
Technical Summary
Steeltoe.Management.Endpoint versions 3.2.2, 3.3.0, and 4.1.0 have an authentication bypass vulnerability (CWE-288) when the management endpoints are configured to listen on an alternate port via the Management:Endpoints:Port setting. The middleware responsible for access restriction relies on the HTTP Host header rather than the actual network socket port, which can be manipulated by an attacker to bypass authentication controls. This issue is patched in versions 3.4.0 and 4.2.0. If upgrading immediately is not feasible, adding explicit ASP.NET Core authorization to sensitive actuator endpoints and enforcing Host header validation at the reverse proxy or load balancer are recommended as defense-in-depth measures.
Potential Impact
An attacker can bypass authentication controls on management endpoints by manipulating the HTTP Host header when the endpoints are configured on an alternate port. This could lead to unauthorized access to sensitive management functions, resulting in high confidentiality impact and limited integrity impact. There is no impact on availability reported. The CVSS v3.1 base score is 8.2 (High).
Mitigation Recommendations
Upgrade to Steeltoe.Management.Endpoint versions 3.4.0 or 4.2.0 where this vulnerability is patched. If immediate upgrade is not possible, apply explicit ASP.NET Core authorization (RequireAuthorization) to all sensitive actuator endpoints. Additionally, configure the reverse proxy or load balancer to enforce the Host header value and prevent clients from setting arbitrary ports to mitigate the risk of authentication bypass.
CVE-2026-50194: CWE-288: Authentication Bypass Using an Alternate Path or Channel in SteeltoeOSS Steeltoe.Management.Endpoint
Description
Steeltoe.Management.Endpoint versions 3.2.2, 3.3.0, and 4.1.0 contain an authentication bypass vulnerability when configured to listen on an alternate port. The middleware incorrectly uses the HTTP Host header instead of the actual network socket port to restrict access, allowing potential unauthorized access to management endpoints. Versions 3.4.0 and 4.2.0 address this issue. Mitigations include upgrading to patched versions or applying explicit ASP.NET Core authorization and configuring reverse proxies to validate the Host header.
CVSS v3.1
Score 8.2high
Affected software
pkg:nuget/SteeltoeOSS/steeltoe.management.endpointRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Steeltoe.Management.Endpoint versions 3.2.2, 3.3.0, and 4.1.0 have an authentication bypass vulnerability (CWE-288) when the management endpoints are configured to listen on an alternate port via the Management:Endpoints:Port setting. The middleware responsible for access restriction relies on the HTTP Host header rather than the actual network socket port, which can be manipulated by an attacker to bypass authentication controls. This issue is patched in versions 3.4.0 and 4.2.0. If upgrading immediately is not feasible, adding explicit ASP.NET Core authorization to sensitive actuator endpoints and enforcing Host header validation at the reverse proxy or load balancer are recommended as defense-in-depth measures.
Potential Impact
An attacker can bypass authentication controls on management endpoints by manipulating the HTTP Host header when the endpoints are configured on an alternate port. This could lead to unauthorized access to sensitive management functions, resulting in high confidentiality impact and limited integrity impact. There is no impact on availability reported. The CVSS v3.1 base score is 8.2 (High).
Mitigation Recommendations
Upgrade to Steeltoe.Management.Endpoint versions 3.4.0 or 4.2.0 where this vulnerability is patched. If immediate upgrade is not possible, apply explicit ASP.NET Core authorization (RequireAuthorization) to all sensitive actuator endpoints. Additionally, configure the reverse proxy or load balancer to enforce the Host header value and prevent clients from setting arbitrary ports to mitigate the risk of authentication bypass.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T22:05:13.645Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a33168ef198dc38c1148dc4
Added to database: 06/17/2026, 21:50:06 UTC
Last enriched: 07/02/2026, 23:07:45 UTC
Last updated: 07/19/2026, 17:26:49 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.