MEDIUM
vvbbnn00
CVE published 2026-09-13
CVE-2026-90504
A vulnerability was found in the WARP-Clash-API project, affecting the function's authorized argument SECRET_KEY, which leads to missing authentication. The attack can be initiated remotely, and the exploit has been disclosed to the public. The product uses continuous delivery with rolling releases, so no version details of affected or updated releases are available. The vendor did not respond to early disclosure.