Description
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass / Unauthorized Access
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is in the _authorize_http_key function of the custom_auth_handler module. It causes the function to skip authentication checks to the application's resources and represents improper authentication and missing credential management. The bypass can be triggered over HTTP and does not require prior access to the system, allowing remote exploitation.

Affected Systems

All installations of Cheshire Cat AI up to and including version 1.9.2 are vulnerable.

Risk and Exploitability

6.9 indicates moderate severity. EPSS score of < 1% indicates a low probability of exploitation, but the exploit has been publicly disclosed and can be used by attackers. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited widespread exploitation to date, but the public availability of the exploit means the risk remains significant. An attacker can initiate the exploit remotely via HTTP requests, and no privileged access is required.

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cheshire Cat AI to a version newer than 1.9.2 once an official fix is released by the vendor.
  • Implement strict input validation on the user_id parameter used by custom_auth_handler to reject unexpected or malicious values.
  • If a patch is not yet available, enforce authentication on all endpoints that rely on custom_auth_handler or block unauthenticated requests to.
  • Monitor application logs for anomalies that may indicate authentication bypass attempts and configure alerts for suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title cheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authentication
First Time appeared Cheshire-cat-ai
Cheshire-cat-ai cheshire Cat Ai
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:cheshire-cat-ai:cheshire_cat_ai:*:*:*:*:*:*:*:*
Vendors & Products Cheshire-cat-ai
Cheshire-cat-ai cheshire Cat Ai
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Cheshire-cat-ai Cheshire Cat Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:08:09.709Z

Reserved: 2026-09-12T16:38:13.983Z

Link: CVE-2026-90579

cve-icon Vulnrichment

Updated: 2026-09-14T17:07:25.563Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:53.517

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:31Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function