Description
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Netty configuration distribution service exposed on TCP port 8283 in super-diamond-server has no authentication mechanism. By simply connecting to the service over TCP, an attacker can retrieve the full configuration of any project, which may contain database passwords, API keys, or other sensitive information. This vulnerability directly compromises confidentiality and can provide an attacker with additional footholds for further exploitation.

Affected Systems

Super‑diamond‑server deployments that expose the Netty configuration distribution service on port 8283 and run any version equal to or lower than 1.3.3 are affected. The issue is confined to the Netty component of super-diamond-server; no other vendors or products are indicated as impacted.

Risk and Exploitability

The EPSS score is unavailable, yet the vulnerability is trivial to exploit: an unauthenticated network connection to the open port reveals private data. The CVE is not listed in CISA KEV, indicating no known widespread exploitation to date. Nonetheless, the lack of authentication combined with the sensitivity of the disclosed data suggests a high residual risk. Any host that can reach the service can easily obtain the configuration unless network isolation or firewall rules are enforced.

Generated by OpenCVE AI on August 26, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the version of super-diamond-server deployed; if it is 1.3.3 or earlier, check for a newer release that adds authentication to the Netty configuration service and upgrade if available.
  • If an upgrade is not immediately viable, block access to TCP port 8283 with a firewall so that only trusted administrative hosts can reach the service.
  • Configure network‑level controls (e.g., VPN or segment‑based ACLs) to restrict connectivity to the host running the service, ensuring only authenticated administrators can connect.

Generated by OpenCVE AI on August 26, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unprotected Netty Configuration Service Exposes Project Settings

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T21:42:34.182Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75329

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T22:16:29.087

Modified: 2026-08-26T22:16:29.087

Link: CVE-2026-75329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:45:03Z

Weaknesses

No weakness.