
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77915 is a critical authentication bypass vulnerability in rConfig Core that allows unauthenticated attackers to self-register accounts with full Administrator privileges. It affects rConfig Core versions 8.0.0 through 8.2.9 (fixed in 8.2.10). The flaw was introduced in November 2025 with multiple SSO provider work and publicly disclosed on August 24, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory, rConfig Advisory).
The root cause is a duplicate, unqualified Auth::routes() call in routes/web.php that sits below an earlier Auth::routes(['register' => false]) call (CWE-306: Missing Authentication for Critical Function; CWE-1188: Insecure Default Initialization of Resource). Because Laravel does not deduplicate or retract routes, the second call re-registers the default authentication routes and reinstates the POST /register endpoint that was explicitly disabled. Compounding the issue, the registration controller — inherited from Laravel's RegistersUsers scaffold — does not assign a role upon account creation, and the users.role database column defaults to Admin, meaning any newly registered account automatically receives full administrator privileges with no invitation, approval, or email verification required (rConfig Advisory, GitHub Advisory).
Successful exploitation grants an unauthenticated remote attacker a fully privileged Administrator account on the rConfig instance, with immediate authenticated access upon registration. Because rConfig stores credentials for production network devices, an attacker gains access to those stored device credentials, other users' data, and the ability to issue API tokens — enabling lateral movement into managed network infrastructure. The combination of full confidentiality, integrity, and availability impact makes this a complete system compromise of the rConfig platform and potentially all devices it manages (rConfig Advisory, GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been confirmed as of the disclosure date (GitHub Advisory). The vulnerability is fully automatable — requiring no privileges, no user interaction, and no special conditions — making it trivially exploitable at scale once targeted. The EPSS score is approximately 0.405% (34th percentile), indicating a moderate near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory).
/register on the target instance. A 200 OK response with a registration form confirms the endpoint is active and the instance is likely vulnerable./register with standard registration fields (name, email, password, password_confirmation). No authentication token or invitation code is required.users.role column defaults to Admin. The response sets an authenticated session cookie, logging the attacker in immediately with full Administrator privileges./register from external or unrecognized IP addresses; successful 200/302 responses to POST /register when self-registration should be disabled.POST /register requests followed by authenticated session activity from the same IP; application logs recording new user creation events with role = Admin and is_socialite = 0.users table with role = 'Admin', is_socialite = 0, and a created_at timestamp after November 2025 that no administrator provisioned — query: SELECT id, name, email, role, is_socialite, created_at FROM users ORDER BY created_at;The primary fix is to upgrade rConfig Core to version 8.2.10 or later, which removes the duplicate Auth::routes() call, removes the unused registration controller, and changes the users.role column default from Admin to User (rConfig Releases). Important: upgrading alone does not remove attacker-created accounts — administrators must audit the users table for unrecognized Admin accounts (role = 'Admin', is_socialite = 0) and treat all stored device credentials as compromised if a rogue account is found. As an immediate workaround for installations that cannot be upgraded, block the /register endpoint at the reverse proxy or load balancer. Additional security improvements are available in later releases (8.2.13 and 8.2.14) addressing API credential exposure and file permission issues (rConfig Advisory).
The vulnerability was reported by security researcher QwesiRED and assigned by VulnCheck. A brief community discussion appeared on Reddit's r/pwnhub CVE daily brief on August 25, 2026. No significant vendor statements beyond the official advisory or notable analyst commentary have been identified at this time (rConfig Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."