Junglewise Threat Intelligence

CVE-2026-77915: rConfig Core unauthenticated self-registration with Admin privilege escalation

CVE-2026-77915 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

rConfig Core is a network configuration management platform that stores credentials for production network devices. A critical flaw in versions 8.0.0 through 8.2.9 allows anyone to register a new administrator account without authentication or approval, granting immediate access to all stored device credentials, user data, and API token issuance capabilities. An attacker can create an account and gain full system privileges in seconds, effectively compromising the entire infrastructure management system.

Technical details

The vulnerability is a route registration bypass in Laravel routing. A duplicate, unqualified Auth::routes() call in routes/web.php sits below an earlier Auth::routes(['register' => false]) declaration. Laravel does not deduplicate routes, so the later call re-registers default authentication routes and reinstates the POST /register endpoint that was explicitly disabled. The registration controller inherits from the framework's RegistersUsers scaffold without assigning a role, and the users.role column defaults to Admin, causing any self-registered account to automatically receive Administrator privileges. An unauthenticated attacker can POST to /register, create a fully privileged Admin account, and gain authenticated access with no verification steps. The vulnerability was introduced in November 2025 with SSO provider work and affects all 8.x releases before 8.2.10. Patches are available in version 8.2.10 and later; however, upgrading does not remove maliciously created admin accounts, requiring manual audit of the users table.

Affected products

  • rConfig rConfig Core 8.0.0 through 8.2.9

Timeline

  • 2026-08-10: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-w3hx-9cxg-5ccr
  • 2026-08-10: patched: Fixed in rConfig Core 8.2.10

References

Related threats