CRITICAL
seriousm4x
CVE published 2026-08-13
CVE-2026-49819
A critical vulnerability was found in UpSnap, a wake on lan web app, versions 4.4.1 through 5.3.5. The vulnerability allows an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution. This vulnerability is caused by a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/h [truncated]