Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91997— evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass

Quick assessment

Affected
evolution-foundation evolution-api
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Evolution API 在 2.3.7 及以下版本中,其 中间件存在数组比较逻辑错误,导致比较结果始终为 false,从而允许未认证用户访问 端点。攻击者可以绕过 IP 白名单限制,获取敏感指标数据,包括服务器版本、数据库客户端名称、已配置的服务器 URL 以及 WhatsApp 实例详细信息。

CVSS 5.3 · Medium EPSS 0.34% · P27

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
evolution-foundation evolution-api ≤ 2.3.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91997

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的比较
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
evolution-foundation evolution-api 0 ~ 2.3.7 -

II. Public POCs for CVE-2026-91997

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91997

登录查看更多情报信息。

Patches & Fixes for CVE-2026-91997 (1)

Vendor Advisories for CVE-2026-91997 (1)

Vendor Pages for CVE-2026-91997 (1)

Other References for CVE-2026-91997 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91997

No comments yet


Leave a comment