Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16895— Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails

Quick assessment

Affected
Rapid7 Metasploit-framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Metasploit 框架的 JSON-RPC Web 服务接口中,发现了一个逻辑漏洞(故障开放条件)。当数据库健康检查(db.check)过程中发生异常,且环境变量 MSF_WS_JSON_RPC_API_TOKEN 未被显式设置时,应用程序会将内部状态标志 msf.auth_initialized 重置为 false。ApiToken Warden 认证策略将该 false 值误解为“认证未初始化或无需认证”的指示,从而向 JSON-RPC 请求分发器授予了未经身份验证的本地访问权限。

CVSS 5.1 · Medium

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16895

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails
Source: CVE Program / CVE List V5
Vulnerability Description
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用基本弱点进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Rapid7 Metasploit-framework 0 ~ 6.5.2 -

II. Public POCs for CVE-2026-16895

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16895

登录查看更多情报信息。

Patches & Fixes for CVE-2026-16895 (1)

Proof of Concept for CVE-2026-16895 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16895

No comments yet


Leave a comment