Junglewise Threat Intelligence

CVE-2026-80349: TarsCloud TarsWeb authentication bypass via X-Forwarded-For header

CVE-2026-80349 · Severity: critical · CVSS 9.8 · Published 2026-08-26

Executive brief

TarsWeb is a web dashboard for managing TARS microservices infrastructure. An attacker can bypass all authentication and authorization checks by spoofing a loopback IP address in a request header and specifying an existing administrator account name, gaining unauthorized access to user management, service configuration, package deployment, and other critical administrative functions without providing any credentials.

Technical details

The vulnerability is an authentication bypass caused by improper trust of the X-Forwarded-For header combined with overly permissive SSO middleware logic. The app.js file enables Koa's proxy option without restricting which upstream proxies are trusted or limiting forwarded-hop depth, causing Koa to extract the client IP from an attacker-controlled X-Forwarded-For header. The SSO middleware in midware/ssoMidware.js uses this untrusted IP to check against an allowlist that includes the loopback address (127.0.0.1), and when a match occurs, it assigns the account identity from a uid query parameter without validating any ticket, cookie, or password. An attacker can forge an X-Forwarded-For header with value 127.0.0.1, supply a uid parameter naming an existing account (such as an administrator), and reach any protected route as that account. The fix in version 3.0.16 separates the branches so that allowlist matches assign only a hardcoded default account rather than one controlled by the attacker.

Affected products

  • TarsCloud TarsWeb before 3.0.16

Timeline

  • 2026-08-26: disclosed: CVE-2026-80349 published on NVD
  • 2026: patched: Fix available in version 3.0.16

References

Related threats