CVE-2026-102245 Details
Description
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A missing authentication vulnerability has been identified in MODSetter SurfSense versions through 2.0.3. The issue resides in the Circleback webhook endpoint, specifically in the FastAPI backend. The vulnerability allows unauthenticated users to send requests that are processed without proper authentication or authorization checks. This flaw can be exploited remotely, leading to unauthorized access and manipulation of application data.
To address this vulnerability, it is recommended to implement per-workspace HMAC or shared secret requirements for Circleback webhook POST requests, ensuring that missing or invalid signatures are rejected. Workspaces without a Circleback connector should return a 404 error. Additionally, the route should be disabled or unmounted until the signing requirement is implemented.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/DReazer/1e476832e48bcdb2b4f732689dfeac0c | [email protected] | ExploitRemedy |
| https://vuldb.com/cve/CVE-2026-102245 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/933653 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411143 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411143/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MODSetter SurfSense | 0.0.36 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion