SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-31309

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

The vulnerability in Mysterium Node allows unauthenticated attackers to exploit improper authorization in the /tequilapi/config/user endpoint, enabling them to overwrite the node's configuration and potentially take full control of the node through a specially crafted POST request. This critical flaw affects all versions from v1.21.1-rc0 up to, but not including, v1.36.0. Organizations using Mysterium Node should prioritize patching to mitigate the risk of unauthorized access and control over their nodes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-31309
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.