Executive brief
A gRPC server implementation exposes a dangerous function that can be called by unauthenticated attackers to gain elevated privileges on the affected system. This vulnerability allows an attacker with network access to bypass authorization controls and execute operations with higher privileges than intended, potentially leading to full system compromise.
Technical details
A gRPC service exposes a privileged function without proper access controls, allowing unauthenticated or unprivileged network callers to invoke operations intended for administrative use only. The vulnerability stems from insufficient authorization validation on the exposed RPC method. Exploitation requires only network connectivity to the gRPC server endpoint.
Affected products
- <UNKNOWN>
Timeline
- 2026-09-22: disclosed