PatchSiren cyber security CVE debrief
CVE-2026-49864 butlerx CVE debrief
CVE-2026-49864 is a high-severity vulnerability in the wetty terminal access service. The vulnerability allows an attacker to inject script into the victim's browser and execute arbitrary keystrokes in their SSH session. This CVE was published on 2026-08-13T20:17:22.720Z and was last modified on 2026-09-09T21:02:22.660Z. Affected product deployments should be reviewed for exposure, and owners should prioritize patching to version 3.0.4 or later. The vulnerability exists due to improper handling of base64 filenames in the file-download escape sequence, which can lead to script injection and unauthorized keystrokes in SSH sessions.
- Vendor
- butlerx
- Product
- wetty
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for SSH session security and wetty service administration should assess exposure and prioritize patching to version 3.0.4 or later. Operators, platforms, vulnerability-management teams, and security teams may be impacted by this vulnerability and should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
CVE-2026-49864 is a high-severity vulnerability in the wetty terminal access service that allows an attacker to inject script into the victim's browser and execute arbitrary keystrokes in their SSH session. Defenders responsible for SSH session security and wetty service administration should assess exposure and prioritize patching to version 3.0.4 or later.
- attacker can inject script into victim's browser
- attacker can execute arbitrary keystrokes in victim's SSH session
- patching to version 3.0.4 or later is required
Technical summary
The wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string. This allows an attacker to inject script into the victim's browser and execute arbitrary keystrokes in their SSH session. The vulnerability can be mitigated by patching to version 3.0.4 or later and verifying SSH session security. Affected product context and defensive impact should be considered when assessing exposure and prioritizing patching. The vulnerability class is related to improper handling of user input in the wetty terminal access service.
Defensive priority
Defenders should prioritize patching to version 3.0.4 or later and verify SSH session security.
Recommended defensive actions
- Patch wetty to version 3.0.4 or later
- Verify SSH session security
- Monitor for suspicious activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from the CVE record and NVD detail page indicates that the vulnerability exists in versions prior to 3.0.4 and that patching is required. The CVE record and NVD detail page provide source-provided CVE metadata and official NIST NVD detail page and source-specific vulnerability assessment. Defenders should verify SSH session security and review compensating controls for exposed systems while remediation is scheduled and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49864 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49864
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49864 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49864
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/butlerx/wetty/security/advisories/GHSA-p26j-h7wj-r568
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.