Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103244

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Oct 01, 2026
Vendor unknown

Description

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.

References