Junglewise Threat Intelligence

CVE-2026-7167: Gaudire Assassin game improper authentication in email validation

CVE-2026-7167 · Severity: info · CVSS 6.9 · Published 2026-06-22

Technologies: Gaudire Assassin game. Vendors: Gaudire.

Executive brief

Gaudire Assassin game is an interactive gaming platform. A security flaw allows users to register accounts using fake or unverified email addresses. This can lead to the mass creation of fraudulent accounts, which may be used for spam distribution, system abuse, or to bypass standard user controls.

Technical details

The vulnerability exists in the authentication process of Gaudire's Assassin game due to improper validation of the 'email' field. A remote, unauthenticated attacker can register accounts using arbitrary or fake email addresses because the system does not verify the ownership or validity of the provided address. This lack of validation facilitates the mass creation of fraudulent accounts. Once registered, an attacker can exploit the platform for spam distribution, system abuse, or to circumvent user management controls. As of the advisory date, no patch or solution has been reported.

Affected products

  • Gaudire Assassin game last version

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References

Related threats