PatchSiren

seriousm4x CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL seriousm4x CVE published 2026-08-13

CVE-2026-49819

A critical vulnerability was found in UpSnap, a wake on lan web app, versions 4.4.1 through 5.3.5. The vulnerability allows an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution. This vulnerability is caused by a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/h [truncated]