CVE-2026-33950 Details
Description
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, allowing them to modify sensitive vessel routing data, alter server configurations, and access restricted endpoints. This issue has been patched in version 2.24.0-beta.4.
A privilege escalation vulnerability has been identified in Signal K Server versions prior to 2.24.0-beta.4. This vulnerability allows an unauthenticated attacker to inject an admin role through the /enableSecurity endpoint, which remains open even after the initial setup of an admin account. Exploitation of this vulnerability grants full administrator access, enabling the attacker to modify sensitive vessel routing data, change server configurations, and access restricted endpoints.
Users are advised to update to Signal K Server version 2.24.0-beta.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SignalK/signalk-server/releases/tag/v2.24.0-beta.4 | [email protected] | ProductRelease Notes |
| https://github.com/SignalK/signalk-server/security/advisories/GHSA-x8hc-fqv3-7gwf | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| signalk signal k server | < 2.24.0 2.24.0 beta1 2.24.0 beta2 2.24.0 beta3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |