Junglewise Threat Intelligence

CVE-2026-90509: dromara orion-visor hardcoded credential authentication bypass

CVE-2026-90509 · Severity: high · CVSS 7.3 · Published 2026-09-13

Vendors: Dromara.

Executive brief

Orion-visor is a lightweight bastion host and operations automation platform for managing servers via SSH, RDP, VNC and other protocols. The product contains hardcoded default authentication tokens in its source code that allow remote attackers to bypass authentication and access sensitive agent-facing APIs, potentially gaining unauthorized control over monitored servers and their management functions.

Technical details

A hardcoded credential vulnerability exists in the ExposeApiAspect.beforeExposeApi() function in orion-visor up to version 2.5.7. The application uses a custom authentication mechanism via @ExposeApi annotations for internal agent-facing APIs; however, when the API_EXPOSE_TOKEN environment variable is not set, the system falls back to a hardcoded default token (pmqeHOyZaumHm0Wt) visible in the public source code. An unauthenticated remote attacker can supply this token in the request header to bypass authentication and access multiple critical endpoints, including those for agent state management (setAgentOnline, setAgentOffline, setAgentHeartbeat) and host monitoring (addMetrics, syncHostMeta). No patch has been released as of the advisory date, and the project has not yet responded to the early disclosure.

Affected products

  • dromara orion-visor up to 2.5.7

Timeline

  • 2026-07-31: disclosed: Vulnerability reported via GitHub issue #170
  • 2026-09-13: advisory: CVE-2026-90509 published
  • 2026-09-13: other: Public exploit available; no vendor response to early disclosure

References

Related threats