Impact
Covenant up to version 0.6 exposes the CovenantHub SignalR endpoint without an authentication guard. Unauthenticated callers can invoke the CreateHttpListener method and obtain a signed JWT token. Possession of this token allows the caller to authenticate against the entire operator API, granting read and write access to grunts, credentials, binaries, events, and the operator roster. This flaw represents a complete loss of authentication for a critical privileged function, yielding full control over the compromised environment.
Affected Systems
The vulnerability affects the Covenant product released by cobbr, specifically all installations running version 0.6. The vulnerability is tied to the CovenantHub SignalR hub defined in CovenantHub.cs. No other versions or products are currently listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a high-severity risk that would lead to complete compromise. Although the EPSS score is reported as less than 1%, the flaw remains formally unlisted in CISA’s KEV catalog, suggesting low current exploit prevalence but not guaranteeing absence of future attacks. The likely attack vector is remote: any network host able to reach the SignalR hub can abuse it without credentials. The exploit requires no special privileges or user interaction beyond contacting the exposed method. Because the vulnerability is easily accessible and has a low surface in terms of prerequisites, any compromise of network access to the CovenantHub endpoint could result in immediate full control of the operator experience.
OpenCVE Enrichment