CVE-2026-77915: 
rConfig vulnerability analysis and mitigation

Overview

CVE-2026-77915 is a critical authentication bypass vulnerability in rConfig Core that allows unauthenticated attackers to self-register accounts with full Administrator privileges. It affects rConfig Core versions 8.0.0 through 8.2.9 (fixed in 8.2.10). The flaw was introduced in November 2025 with multiple SSO provider work and publicly disclosed on August 24, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, rConfig Advisory).

Technical details

The root cause is a duplicate, unqualified Auth::routes() call in routes/web.php that sits below an earlier Auth::routes(['register' => false]) call (CWE-306: Missing Authentication for Critical Function; CWE-1188: Insecure Default Initialization of Resource). Because Laravel does not deduplicate or retract routes, the second call re-registers the default authentication routes and reinstates the POST /register endpoint that was explicitly disabled. Compounding the issue, the registration controller — inherited from Laravel's RegistersUsers scaffold — does not assign a role upon account creation, and the users.role database column defaults to Admin, meaning any newly registered account automatically receives full administrator privileges with no invitation, approval, or email verification required (rConfig Advisory, GitHub Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker a fully privileged Administrator account on the rConfig instance, with immediate authenticated access upon registration. Because rConfig stores credentials for production network devices, an attacker gains access to those stored device credentials, other users' data, and the ability to issue API tokens — enabling lateral movement into managed network infrastructure. The combination of full confidentiality, integrity, and availability impact makes this a complete system compromise of the rConfig platform and potentially all devices it manages (rConfig Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been confirmed as of the disclosure date (GitHub Advisory). The vulnerability is fully automatable — requiring no privileges, no user interaction, and no special conditions — making it trivially exploitable at scale once targeted. The EPSS score is approximately 0.405% (34th percentile), indicating a moderate near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing rConfig Core instances (versions 8.0.0–8.2.9) using tools like Shodan or Censys by searching for rConfig login pages or HTTP response fingerprints.
  2. Confirm vulnerable endpoint: Send a GET request to /register on the target instance. A 200 OK response with a registration form confirms the endpoint is active and the instance is likely vulnerable.
  3. Submit registration request: Send a crafted HTTP POST request to /register with standard registration fields (name, email, password, password_confirmation). No authentication token or invitation code is required.
  4. Obtain Administrator session: The registration controller creates the account without assigning a role, so the users.role column defaults to Admin. The response sets an authenticated session cookie, logging the attacker in immediately with full Administrator privileges.
  5. Access sensitive data: Use the Administrator session to browse stored device credentials, enumerate user accounts, extract API tokens, or reconfigure managed network devices via the rConfig interface (rConfig Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /register from external or unrecognized IP addresses; successful 200/302 responses to POST /register when self-registration should be disabled.
  • Logs: Web server access logs showing POST /register requests followed by authenticated session activity from the same IP; application logs recording new user creation events with role = Admin and is_socialite = 0.
  • Database: Presence of user accounts in the users table with role = 'Admin', is_socialite = 0, and a created_at timestamp after November 2025 that no administrator provisioned — query: SELECT id, name, email, role, is_socialite, created_at FROM users ORDER BY created_at;
  • Application Behavior: Unexpected API token issuance events; unauthorized access to device credential stores or configuration exports shortly after an unrecognized account was created (rConfig Advisory).

Mitigation and workarounds

The primary fix is to upgrade rConfig Core to version 8.2.10 or later, which removes the duplicate Auth::routes() call, removes the unused registration controller, and changes the users.role column default from Admin to User (rConfig Releases). Important: upgrading alone does not remove attacker-created accounts — administrators must audit the users table for unrecognized Admin accounts (role = 'Admin', is_socialite = 0) and treat all stored device credentials as compromised if a rogue account is found. As an immediate workaround for installations that cannot be upgraded, block the /register endpoint at the reverse proxy or load balancer. Additional security improvements are available in later releases (8.2.13 and 8.2.14) addressing API credential exposure and file permission issues (rConfig Advisory).

Community reactions

The vulnerability was reported by security researcher QwesiRED and assigned by VulnCheck. A brief community discussion appeared on Reddit's r/pwnhub CVE daily brief on August 25, 2026. No significant vendor statements beyond the official advisory or notable analyst commentary have been identified at this time (rConfig Advisory).

Additional resources


Source: This report was generated using AI

Related rConfig vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77915CRITICAL9.3
  • rConfig logorConfig
  • cpe:2.3:a:rconfig:rconfig
NoYesAug 24, 2026
CVE-2023-39110HIGH8.8
  • rConfig logorConfig
  • cpe:2.3:a:rconfig:rconfig
NoYesAug 01, 2023
CVE-2026-77914HIGH7.1
  • rConfig logorConfig
  • cpe:2.3:a:rconfig:rconfig
NoYesAug 24, 2026
CVE-2026-64826HIGH7.1
  • rConfig logorConfig
  • cpe:2.3:a:rconfig:rconfig
NoYesAug 12, 2026
CVE-2026-63102MEDIUM5.3
  • rConfig logorConfig
  • cpe:2.3:a:rconfig:rconfig
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management