HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-66420 — MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v...

·Source: NIST NVD

Updated:

Executive Summary

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th

Analysis

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance. CVSS Score: 8.8. Published: 2026-07-30T23:16:53.527.

Indicators of Compromise (1)

CVE (1)
CVE-2026-66420
Source Attribution

Originally published by NIST NVD on Jul 30, 2026. Verified by: NIST.

Related Threats

MEDIUMVulnerabilityNEW

Defcon Aerospace Village Seeks Broader Appeal This Year

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/defcon-aerospace-village-seeks-broader-appeal-this-year-image_small-2-a-32400.jpg" align=right hspace=4><b>That’s No Moon, It’s an Insecure PLC</b><br>The Aerospace Village at annual hacking conference Defcon, famed as the home of the Hack-A-Sat contest which culminated in 2023 with the live hacking of a real satellite in orbit, w

Bank Info Security
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-61524 — WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerabili...

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the applicat

CVE-2026-61524
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-61523 — WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the D...

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable p

CVE-2026-61523
NIST NVD