Description
A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the get_surge_subscription function of services/subscription.py within the Subscription Handler component of the vvbbnn00 WARP-Clash-API. By manipulating the argument key, an attacker can bypass proper authentication checks and gain unauthorized access to surge subscription data. The weakness originates from improper handling of input authentication and lack of authorization safeguards, as identified by CWE‑266 and CWE‑284.

Affected Systems

The issue impacts the vvbbnn00 WARP-Clash-API product, up to commit c7bf2360073959861219b422e51ae86411051b46. Because the project follows a rolling‑release schedule and the vendor has ceased maintenance for the affected build, specific version numbers are not listed. The Subscription Handler module in services/subscription.py is the exposed component.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of widespread exploitation. However, the vulnerability is publicly documented and the product is no longer supported, which makes any existing deployment at risk for remote attacks targeting the vulnerable endpoint. The lack of official patches or workarounds further raises the overall risk for organizations still operating this API.

Generated by OpenCVE AI on September 15, 2026 at 17:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or remove the get_surge_subscription endpoint until a secure implementation is available.
  • Apply strict input validation and enforce proper authentication and authorization on the argument key, following established access control patterns.
  • Migrate away from the unsupported vvbbnn00 WARP-Clash-API product to a maintained alternative, or seek a supported release if one becomes available.

Generated by OpenCVE AI on September 15, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Title vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control
First Time appeared Vvbbnn00
Vvbbnn00 warp-clash-api
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
Vendors & Products Vvbbnn00
Vvbbnn00 warp-clash-api
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vvbbnn00 Warp-clash-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:36:59.196Z

Reserved: 2026-09-12T08:46:54.990Z

Link: CVE-2026-90507

cve-icon Vulnrichment

Updated: 2026-09-14T15:36:54.307Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T10:16:55.720

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control