CVE-2026-5842 Details
Description
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
A critical authorization bypass vulnerability has been identified in Decolua 9router versions through 0.3.47. The issue arises from improper authentication checks on several administrative API endpoints, allowing remote attackers to access sensitive functions without authorization. This vulnerability can lead to a full compromise of the application, including unauthorized access to database management, API key generation, provider credentials, and application settings. Additionally, it enables server-side request forgery (SSRF) attacks and the ability to remotely shut down the server.
Users are advised to upgrade to Decolua 9router version 0.3.75, which addresses this vulnerability. The updated version can be downloaded from the Decolua 9router GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 9, 2026CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/decolua/9router/ | [email protected] | ProductSource CodeVendor |
| https://github.com/decolua/9router/issues/431 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/decolua/9router/issues/431#issuecomment-4140163867 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/decolua/9router/releases/tag/v0.3.75 | [email protected] | Release NotesVendor |
| https://github.com/deepcat1337/Free_Api_Exploit/tree/main | [email protected] | Exploit |
| https://vuldb.com/submit/790003 | [email protected] | ExploitTechnical Description |
| https://vuldb.com/vuln/356298 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/356298/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| decolua 9router | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |
Volerion