Description
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to Prometheus metrics and disclosure of server configuration
Action: Apply patch
AI Analysis

Impact

The vulnerability arises from an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated callers to reach the /metrics endpoint. Access to this endpoint exposes the server version, database client name, configured server URL, and WhatsApp instance details, resulting in moderate‑severity information disclosure as reflected by a CVSS score of 6.9.

Affected Systems

The issue affects Evolution Foundation’s evolution‑api component up to and including version 2.3.7. Any system running these affected releases is vulnerable, independent of the underlying operating system or deployment environment. The component is typically deployed as a standalone service exposing its Prometheus metrics endpoint.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. However, the lack of authentication combined with the bypass of the IP whitelist means an attacker who can reach the API’s network port can issue a simple HTTP request to /metrics and obtain sensitive data. The vulnerability is not listed in the CISA KEV catalog, but the straightforward attack path and exposed information create a non‑negligible risk for deployments that expose the metrics endpoint.

Generated by OpenCVE AI on September 17, 2026 at 18:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s public patch or upgrade to evolution‑api v2.3.8 or later if available.
  • Verify that the IP allowlist configuration for the /metrics endpoint is correctly applied and that no unintended IPs are permitted access.
  • Place the /metrics endpoint behind a firewall or restrict its exposure to trusted networks; consider disabling it if Prometheus monitoring is not required for operational visibility.

Generated by OpenCVE AI on September 17, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Evolution-foundation
Evolution-foundation evolution-api
Vendors & Products Evolution-foundation
Evolution-foundation evolution-api

Tue, 15 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.
Title evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass
First Time appeared Cs-technologies
Cs-technologies evolution
Weaknesses CWE-697
CPEs cpe:2.3:a:cs-technologies:evolution:*:*:*:*:*:*:*:*
Vendors & Products Cs-technologies
Cs-technologies evolution
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cs-technologies Evolution
Evolution-foundation Evolution-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:36.625Z

Reserved: 2026-09-15T11:11:13.312Z

Link: CVE-2026-91997

cve-icon Vulnrichment

Updated: 2026-09-15T11:54:42.761Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:55.240

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-91997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses