Threats Tagged 'cve-2026-16895'
View all threats tagged with 'cve-2026-16895'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-16895'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-16895: CWE-305 Authentication bypass by primary weakness in Rapid7 Metasploit-frameworkCVE-2026-16895 0 A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher. Join the discussion | CVE Database V5 | 08/27/2026, 03:14:21 UTC Added: 08/27/2026, 04:07:53 UTC |
Showing 1 to 1 of 1 result