Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node API Allows Full Node Takeover

Sat, 25 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node API Allows Full Node Takeover

Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node Allows Unauthenticated Configuration Overwrite

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Mysterium Node Allows Unauthenticated Configuration Overwrite

Thu, 16 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover in Mysterium Node

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover in Mysterium Node

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request. Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
References

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover

Mon, 13 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Full Node Takeover

Sun, 12 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Node Configuration Overwrite and Full Takeover

Fri, 10 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Node Configuration Overwrite and Full Takeover

Fri, 10 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized configuration overwrite via /tequilapi/config/user endpoint
Weaknesses CWE-284

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized configuration overwrite via /tequilapi/config/user endpoint
Weaknesses CWE-284

Wed, 08 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-16T12:21:40.263Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31309

cve-icon Vulnrichment

Updated: 2026-07-09T14:31:10.556Z

cve-icon NVD

Status : Deferred

Published: 2026-07-08T22:17:13.840

Modified: 2026-07-16T13:16:30.707

Link: CVE-2026-31309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:15:03Z

Weaknesses