Description
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

Ground‑station versions prior to 0.8.0 contain a critical authentication bypass that allows an unauthenticated attacker to execute arbitrary SQL statements while the application is in its initial setup mode. By invoking the setup.restore command through Socket.IO, an attacker can create new administrator accounts and place forged session tokens. Once these tokens are in place the attacker can log in as an administrator without credentials, effectively taking full control of the application. The vulnerability is a missing authentication check for a sensitive function (CWE‑306). The CVE description indicates that the vulnerability is exploitable during first‑run setup mode and that Socket.IO is used to invoke the command. It does not specify whether the Socket.IO endpoint is publicly exposed, so we infer that remote exploitation is possible if the interface is reachable from the network.

Affected Systems

The affected product is sgoudelis:ground‑station, any release before 0.8.0. No narrower version list is supplied, so all pre‑0.8.0 builds are considered vulnerable.

Risk and Exploitability

The CVSS score of 9.3 denotes critical severity. The EPSS score is not available, but the lack of a KEV listing indicates it has not yet been widely exploited in the wild. The description does not state whether the Socket.IO interface is publicly exposed; it is inferred that an attacker could trigger the vulnerability remotely if the interface is reachable from the network. Because the attacker can gain unrestricted administrator rights, the impact on confidentiality, integrity, and availability is complete application takeover.

Generated by OpenCVE AI on October 1, 2026 at 14:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to ground‑station version 0.8.0 or newer.
  • Disable the first‑run setup mode or restrict access to the setup.restore endpoint until patched.
  • Limit exposure of the application and Socket.IO interface to trusted networks or enforce network isolation.

Generated by OpenCVE AI on October 1, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
Title ground-station before 0.8.0 Authentication Bypass via setup.restore
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:25:20.227Z

Reserved: 2026-09-30T10:52:32.248Z

Link: CVE-2026-103244

cve-icon Vulnrichment

Updated: 2026-10-01T13:25:04.030Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T11:17:17.503

Modified: 2026-10-01T15:09:04.013

Link: CVE-2026-103244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function