Description
Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.
Published: 2026-10-01
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access leads to disclosure of episode metadata and potential playback disruption
Action: Apply Patch
AI Analysis

Impact

Podgrab exposes a missing authentication flaw where the /ws WebSocket endpoint is attached to the root router instead of the BasicAuth‑protected group. Unauthenticated clients can connect even if a password is set, listen to PlayerExists broadcasts that expose client‑supplied player identifiers, and replay these identifiers in RegisterPlayer messages to hijack queue payloads intended for authenticated users. The attacker thereby gains access to episode IDs, titles, server‑side file paths, and can interfere with legitimate playback.

Affected Systems

AkIlrex Podgrab is affected. No specific affected version information is available; any unpatched Podgrab instance exposing the /ws endpoint is at risk.

Risk and Exploitability

The CVSS score of 6.3 rates this as a medium‑severity vulnerability. The EPSS score is not available, indicating that exploitation likelihood information is incomplete, but the flaw permits straightforward network‑based attacks from any host that can reach the WebSocket endpoint. Because Podgrab frequently runs behind publicly reachable services, attackers can easily exploit the authentication bypass to obtain sensitive metadata and disrupt service for legitimate users. Although this vulnerability is not listed in the CISA KEV catalog, its impact remains significant for exposed installations.

Generated by OpenCVE AI on October 1, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Podgrab release that secures the /ws route under BasicAuth protection.
  • If an upgrade is not immediately possible, constrain inbound traffic to the /ws endpoint with firewall or reverse‑proxy rules so that only trusted clients can connect.
  • As an interim measure, alter the Podgrab configuration or source code to register the /ws endpoint within the BasicAuth‑protected router group, or add authentication middleware to the WebSocket handler.

Generated by OpenCVE AI on October 1, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture PlayerExists broadcasts containing client-supplied player identifiers, and replay them in a RegisterPlayer message to hijack queue payloads intended for authenticated users, exposing episode IDs, titles, and server-side file paths while potentially disrupting legitimate playback.
Title Podgrab Missing Authentication on WebSocket /ws Endpoint
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T18:36:54.420Z

Reserved: 2026-10-01T18:02:50.081Z

Link: CVE-2026-104058

cve-icon Vulnrichment

Updated: 2026-10-01T18:36:51.279Z

cve-icon NVD

Status : Received

Published: 2026-10-01T19:17:19.320

Modified: 2026-10-01T19:17:19.320

Link: CVE-2026-104058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:30:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function