Junglewise Threat Intelligence

CVE-2026-75329: super-diamond-server Netty authentication bypass in configuration service

CVE-2026-75329 · Severity: critical · CVSS 9.8 · Published 2026-08-26

Executive brief

super-diamond-server is a configuration management service that distributes application settings via Netty (a network framework). Versions up to 1.3.3 lack authentication on the configuration distribution port (8283), allowing anyone to remotely read all project configurations including database passwords and API keys without any login credentials.

Technical details

The vulnerability is an authentication bypass (CWE-306) in DiamondServerHandler.channelRead0(), which processes TCP requests on port 8283 without verifying the client's identity. An attacker can send a simple JSON payload specifying a project code and environment profile (e.g., "production") and directly retrieve the complete configuration data. The protocol requires a TCP connection and JSON-formatted request string; no special preconditions or privileges are needed. An attacker with network access to port 8283 can enumerate project codes and dump all configuration files, exposing sensitive credentials and secrets. The vulnerability affects super-diamond-server versions up to and including 1.3.3; patched versions exist post-1.3.3.

Affected products

  • super-diamond super-diamond-server <=1.3.3

Timeline

  • 2026-08-26: disclosed
  • other: CVE-2026-75329 assigned

References

Related threats