Junglewise Threat Intelligence

CVE-2026-82641: Keploy agent control-plane authentication bypass

CVE-2026-82641 · Severity: high · CVSS 8.6 · Published 2026-08-30

Executive brief

Keploy is a testing platform that records and replays API interactions for regression testing. Versions 3.1.0 through 3.6.25 expose sensitive HTTP endpoints on all network interfaces without authentication, allowing attackers to retrieve encrypted TLS session keys, terminate recording sessions, or inject mock data. This could lead to disclosure of network traffic and disruption of testing workflows.

Technical details

The vulnerability is an authentication bypass in the agent's control-plane HTTP server, which binds to 0.0.0.0 (all interfaces) instead of localhost. Affected versions expose unauthenticated endpoints including GET /agent/pcap/keylog (streams TLS session keys for traffic decryption), POST /agent/stop (terminates recording), and POST /agent/storemocks (injects mock data). In native mode, any local process can access these endpoints; in Docker mode, any host reachable via the published container port can exploit them. The fix, released in version 3.6.26, binds the server to loopback (127.0.0.1) in native mode and restricts Docker port publishing to loopback-only on the host.

Affected products

  • Keploy Keploy 3.1.0 through 3.6.25

Timeline

  • 2026-08-30: disclosed
  • 2026-08-29: patched: Fix released in version 3.6.26

References