CVE-2026-31309 Details
Description
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
A vulnerability exists in Mysterium Node versions prior to 1.36.0, specifically within the TequilAPI configuration user endpoint. This vulnerability allows unauthenticated attackers to overwrite the node's configuration arbitrarily. Exploitation involves sending a crafted POST request, which can lead to a complete takeover of the node.
Users can upgrade to Mysterium Node version 1.36.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sch8ill/CVE-2026-31309 | CISA-ADP | ExploitTechnical Description |
| https://github.com/mysteriumnetwork/node/ | [email protected] | ProductSource CodeVendor |
| https://github.com/mysteriumnetwork/node/commit/bc099fcaff59fee9c8a8f8e07ffff5b3c5df2bb9 | [email protected] | Source CodeVendor |
| https://github.com/sch8ill/CVE-2026-31309 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Mysterium Node | < 1.36.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion