CVE-2026-15812
Received Received - Intake

kronosnet ACL Bypass via Spoofed Link ID

Vulnerability report for CVE-2026-15812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Red Hat, Inc.

Description

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kronosnet kronosnet to 1.34 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in kronosnet versions <= 1.34 due to a flaw in the Access Control List (ACL) subsystem. When dynamic links are configured without encryption and accept traffic from any IP, the system trusts the link ID in incoming packets without proper validation. An attacker can spoof a legitimate link ID in crafted network frames to bypass ACL restrictions and inject arbitrary data packets.

Detection Guidance

To detect this vulnerability, monitor network traffic for unencrypted dynamic links in kronosnet. Check for packets with spoofed link IDs by analyzing network frames and validating link ID consistency. Use tools like tcpdump or Wireshark to inspect traffic patterns and identify unauthorized packet injections.

Impact Analysis

An unauthenticated remote attacker could exploit this to bypass security controls and inject malicious data packets. This may lead to data corruption, service instability, or runtime issues in applications relying on kronosnet for communication.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized data injection or corruption. Unencrypted dynamic links and ACL bypass may expose sensitive data to manipulation, violating integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Immediately disable dynamic links without encryption in kronosnet configurations. Ensure all dynamic links use encryption to prevent link ID spoofing. Update kronosnet to the latest patched version if available. Restrict network access to trusted IPs only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart