CRITICAL
cobbr
CVE published 2026-09-16
CVE-2026-92717
CVE-2026-92717 is a critical vulnerability in Covenant, a tool used for red team operations, through version 0.6. The vulnerability allows unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token due to the CovenantHub SignalR hub being registered without an Authorize attribute. This token can be used to authenticate against the entire operator API, granting access to sensitive [truncated]