Description
Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated access grants full operator API credentials, enabling attackers to manage infrastructure
Action: Immediate Patch
AI Analysis

Impact

Covenant up to version 0.6 exposes the CovenantHub SignalR endpoint without an authentication guard. Unauthenticated callers can invoke the CreateHttpListener method and obtain a signed JWT token. Possession of this token allows the caller to authenticate against the entire operator API, granting read and write access to grunts, credentials, binaries, events, and the operator roster. This flaw represents a complete loss of authentication for a critical privileged function, yielding full control over the compromised environment.

Affected Systems

The vulnerability affects the Covenant product released by cobbr, specifically all installations running version 0.6. The vulnerability is tied to the CovenantHub SignalR hub defined in CovenantHub.cs. No other versions or products are currently listed as affected.

Risk and Exploitability

The CVSS score of 9.3 indicates a high-severity risk that would lead to complete compromise. Although the EPSS score is reported as less than 1%, the flaw remains formally unlisted in CISA’s KEV catalog, suggesting low current exploit prevalence but not guaranteeing absence of future attacks. The likely attack vector is remote: any network host able to reach the SignalR hub can abuse it without credentials. The exploit requires no special privileges or user interaction beyond contacting the exposed method. Because the vulnerability is easily accessible and has a low surface in terms of prerequisites, any compromise of network access to the CovenantHub endpoint could result in immediate full control of the operator experience.

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a vendor release or patch that adds an Authorize attribute to the CovenantHub SignalR hub and disables CreateHttpListener for unauthenticated callers
  • If no patch is available, isolate the CovenantHub endpoint from the network by firewall rules or VPN placement to prevent external access until the fix is applied
  • Enable monitoring and alerting for unexpected CreateHttpListener calls, and log any JWT tokens issued to detect potential abuse

Generated by OpenCVE AI on September 18, 2026 at 06:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials, binaries, events, and the operator roster.
Title Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub
First Time appeared Cobbr
Cobbr covenant
Weaknesses CWE-306
CPEs cpe:2.3:a:cobbr:covenant:*:*:*:*:*:*:*:*
Vendors & Products Cobbr
Cobbr covenant
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:51.497Z

Reserved: 2026-09-16T17:20:10.124Z

Link: CVE-2026-92717

cve-icon Vulnrichment

Updated: 2026-09-21T17:51:20.559Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:22.540

Modified: 2026-09-23T17:17:49.120

Link: CVE-2026-92717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function