CVE-2026-103397 Details
Description
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.
A vulnerability exists in OpenSave versions prior to 2.4.0-beta.1, where the application fails to properly authenticate sender identities in WAN relay requests. This flaw allows unpaired room members to impersonate paired devices by manipulating the RelayMessage 'From' field. Attackers aware of the room code can join the room, access paired peer identifiers through announcements, and send forged requests to retrieve protected synchronization routes, including save data, snapshots, and file operations.
Users can update to OpenSave version 2.4.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb | [email protected] | Technical Description |
| https://github.com/Liquid-co/OpenSave | [email protected] | ProductSource CodeVendor |
| https://github.com/Liquid-co/OpenSave/blob/v2.3.1/internal/p2p/wanclient_handlers.go#L268-L282 | [email protected] | Source CodeVendor |
| https://github.com/Liquid-co/OpenSave/commit/2f2612b13233ac123e01a03cb3008c44bacaeae3 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/opensave-before-2.4.0-beta.1-authentication-bypass-via-spoofed-relay-sender | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Liquid-co OpenSave | >= 0, < 2.4.0-beta.1 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion