Junglewise Threat Intelligence

CVE-2026-7165: Gaudire Assassin game multiple vulnerabilities in /addJugador endpoint

CVE-2026-7165 · Severity: info · CVSS 9.4 · Published 2026-06-22

Technologies: Gaudire Assassin game. Vendors: Gaudire.

Executive brief

Gaudire's Assassin game, an interactive platform used for city-sponsored events, contains multiple critical security flaws in its player management system. An attacker can manipulate game scores to fraudulently claim real-world prizes, take over other users' accounts, or grant themselves administrative control over the entire system. Additionally, the flaws allow attackers to crash the game service or access sensitive internal data, potentially disrupting operations and exposing private information.

Technical details

Multiple vulnerabilities exist within the '/addJugador' endpoint of Gaudire's Assassin game due to improper input validation (CWE-20). Authenticated attackers can exploit 'keyJugador' and 'keyJugadorObjectiu' parameters to modify other users' data without authorization. The 'tokens' field allows for self-assignment of administrative privileges, while the 'punts' and 'numObjectiusEliminats' fields permit arbitrary score manipulation. Furthermore, the 'urlImatge' parameter is vulnerable to Server-Side Request Forgery (SSRF), allowing attackers to interact with internal services or read local files. Finally, numeric fields lack length validation, enabling Denial-of-Service (DoS) attacks via resource exhaustion. No patch is currently available.

Affected products

  • Gaudire Assassin game last version

Timeline

  • 2026-06-22: advisory: Advisory published by INCIBE-CERT
  • 2026-06-22: disclosed

References

Related threats