Description
A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-09-13
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Race Condition
Action: Monitor
AI Analysis

Impact

The vulnerability is a race condition in the Save Account Job function of vvbbnn00 WARP‑Clash‑API. Remote attackers can trigger a timing mismatch that may lead to inconsistent or corrupted account data. The flaw requires high attack complexity and is considered difficult to exploit, yet it has been publicly disclosed and could be used if an opportunity arises.

Affected Systems

vvbbnn00 WARP‑Clash‑API is affected, with the issue present in releases up to commit c7bf2360073959861219b422e51ae86411051b46. Because the product follows a rolling-release model, specific version details are not listed, and the flaw only impacts releases that are no longer supported by the maintainer.

Risk and Exploitability

3 the severity is low, the EPSS score is < 1%, indicating a very low probability of exploitation. The attack vector is remote, requiring high complexity and difficult exploitability. Even though the risk is low, the public disclosure means the vulnerability could still be exploited against unsupported installations.

Generated by OpenCVE AI on September 15, 2026 at 17:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest available patch for WARP‑Clash‑API once a vendor fix is released.
  • Disable or restrict the use of the Save Account Job feature.
  • Continuously monitor system logs for anomalous account behavior or inconsistent data that may indicate a race condition exploitation.

Generated by OpenCVE AI on September 15, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Title vvbbnn00 WARP-Clash-API Save Account Job race condition
First Time appeared Vvbbnn00
Vvbbnn00 warp-clash-api
Weaknesses CWE-362
CPEs cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
Vendors & Products Vvbbnn00
Vvbbnn00 warp-clash-api
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vvbbnn00 Warp-clash-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T13:59:35.201Z

Reserved: 2026-09-12T08:46:51.858Z

Link: CVE-2026-90506

cve-icon Vulnrichment

Updated: 2026-09-16T13:59:25.583Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T10:16:55.540

Modified: 2026-09-16T14:17:13.650

Link: CVE-2026-90506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')