Junglewise Threat Intelligence

CVE-2026-15541: will-moss Isaiah authentication bypass in Master Websocket Handler

CVE-2026-15541 · Severity: high · CVSS 7.3 · Published 2026-07-13

Executive brief

Isaiah, a web-based tool for managing Docker container fleets, contains a security flaw in how it handles remote commands. In multi-node setups, the central management server fails to verify a user's identity before forwarding commands to connected worker nodes. This could allow an unauthorized person to bypass login screens and potentially view container logs or manipulate Docker resources on the affected worker nodes.

Technical details

A missing authorization check exists in the `Server.Handle` function within `app/server/server/server.go`. In a Master/Agent deployment, the websocket handler processes commands containing an `Agent` argument and forwards them to the target agent before reaching the session authentication gate. An unauthenticated remote attacker can send a crafted websocket command to the Master's `/ws` endpoint to proxy commands to any registered Agent. While the impact is partially mitigated if Agent-side authentication is enabled, the flaw allows attackers to bypass the Master as a central access control point, potentially leading to unauthorized Docker resource access if Agent-level security is weak or disabled. A fix has been proposed in Pull Request #35 but is currently awaiting acceptance.

Affected products

  • will-moss Isaiah up to 1.36.9

Timeline

  • 2026-06-10: disclosed: Issue and Pull Request opened on GitHub
  • 2026-07-13: advisory: NVD/VulDB publication date

References

Related threats