CVE-2026-97231 Details
Description
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in Volotat Anagnorisis versions up to 0.3.1 and 0.4.0, where an unknown function in 'app.py' related to the Socket.IO connect interface lacks proper authentication. This flaw allows remote exploitation, bypassing the HTTP Basic Authentication that is otherwise enforced on standard Flask routes. As a result, unauthenticated clients can access sensitive application functionality and data.
To address this vulnerability, authenticate the Socket.IO handshake, apply authorization to all security-sensitive events, remove the wildcard Origin policy, and add integration tests to ensure consistent access decisions between HTTP and Socket.IO.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://note-hxlab.wetolink.com/share/y74Vzt1jfkAi | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-97231 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908265 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/409321 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/409321/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| volotat Anagnorisis | >= 0.3.1, <= 0.4.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion