CVE-2026-49819

Summary

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in pb.HandlerInitSuperuser (backend/pb/handlers.go:249), reachable as POST /api/upsnap/init-superuser. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a totalSuperusers > 0 count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at backend/networking/wake.go:43 (exec.CommandContext(ctx, "/bin/sh", "-c", wake_cmd)). Version 5.4.0 fixes the issue.

Affected Software

VendorProductVersion RangeStatus
seriousm4xUpSnap>= 4.4.1, < 5.4.0affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CWE-269: CWE-269: Improper Privilege Management
  • CWE-306: CWE-306: Missing Authentication for Critical Function
  • CWE-862: CWE-862: Missing Authorization

References