/Vulnerability Library

9router <=0.5.4 - Authentication Bypass

CVE-2026-56681
Early Release

Description

9Router prior to 0.5.6 contains an authentication bypass caused by trusting client-supplied X-9r-Real-Ip header in src/dashboardGuard.js, letting remote unauthenticated attackers access local API routes and consume resources, exploit requires bypassing API-key validation via header manipulation.

Severity

High

CVSS Score

7.3

Published Date

September 23, 2026

Template Author

0x_akoko

CVE-2026-56681.yaml
7.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE ID:
cve-2026-56681
CWE ID:
cwe-807

References

https://github.com/advisories/GHSA-5mj8-gf6m-fhw8https://github.com/decolua/9router/security/advisories/GHSA-5mj8-gf6m-fhw8https://github.com/decolua/9router/commit/efd20be8d81ef2e256a7037f3aa78e6b567b5fd3https://github.com/decolua/9router/releases/tag/v0.5.6

Remediation Steps

Update to version 0.5.6 or later.