Junglewise Threat Intelligence

CVE-2026-15542: will-moss Isaiah improper authentication in WebSocket connection

CVE-2026-15542 · Severity: high · CVSS 7.3 · Published 2026-07-13

Executive brief

Isaiah, a web-based tool for managing Docker container fleets, contains a security flaw in how it verifies user identity when used with a reverse proxy. If the application is not strictly isolated, an attacker can bypass the login screen by providing a fake authentication header in their request. This could allow an unauthorized user to view sensitive container data, access logs, and perform administrative Docker management operations.

Technical details

A vulnerability in will-moss Isaiah up to 1.36.9 involves improper authentication (CWE-287) within the WebSocket connection handler in `app/main.go`. When `FORWARD_PROXY_AUTHENTICATION_ENABLED` is active, the application trusts the identity provided in HTTP headers (e.g., `Remote-User`) without verifying if the request originated from a trusted proxy. An attacker with network access to the Isaiah backend can bypass the authentication flow by manually supplying the configured header during the `/ws` WebSocket handshake. A pull request (#36) has been submitted to introduce a `FORWARD_PROXY_AUTHENTICATION_TRUSTED_PROXIES` IP/CIDR allowlist to mitigate this issue.

Affected products

  • will-moss Isaiah up to 1.36.9

Timeline

  • 2026-06-10: disclosed: Issue and fix pull request opened on GitHub
  • 2026-07-13: advisory: CVE published to NVD dataset

References

Related threats