CRITICAL
yolanmees
CVE published 2026-07-30
CVE-2026-67594
The Spikster project contains a missing authentication vulnerability (CVE-2026-67594) that allows unauthenticated remote attackers to access all API routes. The CipiAuth middleware is registered but never applied to any route in the API routing configuration, leaving approximately 50 unprotected API endpoints. This issue was reported through a source item from Vulncheck, which provided details on the vuln [truncated]