Description
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
Published: 2026-07-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper authorization flaw in the /tequilapi/config/user endpoint of Mysterium Node. Prior to version 1.36.0, the endpoint accepts arbitrary POST requests without any authentication or authorization check, enabling an attacker to overwrite the node’s configuration file. Overwriting the configuration allows the attacker to gain full control of the node, effectively compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑862 (Missing Authorization).

Affected Systems

Mysterium Node versions released from 1.21.1‑rc0 up to, but not including, version 1.36.0 are affected. Any installation of these earlier releases is vulnerable if the /tequilapi/config/user endpoint is exposed to network traffic.

Risk and Exploitability

The CVSS score of 9.8 denotes critical severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low overall exploitation probability at present. Based on the description, it is inferred that the attack vector is a remote network request to the unsecured endpoint, which an unauthenticated attacker could construct and send to overwrite the node configuration and take over the node.

Generated by OpenCVE AI on July 25, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mysterium Node to version 1.36.0 or later to apply the authorization fix.
  • If an upgrade cannot be performed immediately, block unauthenticated traffic to the /tequilapi/config/user endpoint with firewall rules or network segmentation.
  • Configure the API to require authentication and restrict access to trusted administrators or internal networks.

Generated by OpenCVE AI on July 25, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node API Allows Full Node Takeover

Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node Allows Unauthenticated Configuration Overwrite

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node Allows Unauthenticated Configuration Overwrite

Thu, 16 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover in Mysterium Node

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover in Mysterium Node

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request. Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
References

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover

Mon, 13 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover

Sun, 12 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Node Configuration Overwrite and Full Takeover

Fri, 10 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Node Configuration Overwrite and Full Takeover

Fri, 10 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized configuration overwrite via /tequilapi/config/user endpoint
Weaknesses CWE-284

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized configuration overwrite via /tequilapi/config/user endpoint
Weaknesses CWE-284

Wed, 08 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-16T12:21:40.263Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31309

cve-icon Vulnrichment

Updated: 2026-07-09T14:31:10.556Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:00:14Z

Weaknesses