PatchSiren

cobbr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL cobbr CVE published 2026-09-16

CVE-2026-92717

CVE-2026-92717 is a critical vulnerability in Covenant, a tool used for red team operations, through version 0.6. The vulnerability allows unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token due to the CovenantHub SignalR hub being registered without an Authorize attribute. This token can be used to authenticate against the entire operator API, granting access to sensitive [truncated]