CVE-2026-108549
Deferred Deferred - Pending Action

Unauthenticated Command Injection in cc-connect MAX Platform Adapter

Vulnerability report for CVE-2026-108549, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chenhg5 cc-connect 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108549 is a missing authentication vulnerability in cc-connect through version 1.5.0. It affects the MAX platform adapter's webhook mode in the platform/max/max.go file. When no webhook_secret is configured, the system accepts unauthenticated updates. Attackers can forge updates with allowed or admin user IDs to execute privileged commands like /shell on the host via the webhook listener on port 8080.

Detection Guidance

Check if cc-connect is running on port 8080 without authentication. Use netstat or ss to verify listening ports. Inspect webhook configurations in platform/max/max.go for missing webhook_secret validation. Monitor logs for unauthenticated webhook events or unexpected /shell command executions.

Impact Analysis

This vulnerability allows remote attackers to impersonate authorized users and execute privileged commands on the host system. If you use cc-connect with MAX webhook mode without a webhook_secret, an attacker could gain control over your system, run unauthorized commands, or access sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access and command execution, violating data integrity and confidentiality. For GDPR, it risks unauthorized data processing or exposure. For HIPAA, it may compromise protected health information. Compliance failures could result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade cc-connect to a version beyond 1.5.0 where webhook_secret is required. If upgrading is not possible, configure a strong webhook_secret immediately. Disable webhook mode if unused. Restrict network access to port 8080 via firewall rules. Monitor for suspicious activity and revoke any unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108549. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart