S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 6, 2026

CVE-2026-0650 Scanner

CVE-2026-0650 Scanner - Path Traversal vulnerability in OpenFlagr

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-0650
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Flagrby OpenFlagr
0
Updated Sep 6, 2026View on NVD →
Detail

OpenFlagr is utilized by developers and enterprises to manage feature flags, allowing for dynamic control over the deployment and configuration of application components. The software provides a user-friendly interface that aids in enabling, disabling, or adjusting features in real-time without code changes. OpenFlagr is often integrated into CI/CD pipelines to facilitate automated feature management. Software engineers and product teams leverage OpenFlagr to enhance agility and reduce risk during deployments. The tool is generally deployed on production environments, emphasizing its need for robust security measures. Ensuring secure access to feature flags is critical to maintaining operational integrity and preventing unauthorized alterations.

The Path Traversal vulnerability identified in OpenFlagr allows attackers to bypass authentication mechanisms through improper path normalization. This vulnerability stems from flaws in the HTTP middleware whitelist logic, which processes crafted requests inaccurately. When exploited, attackers can access protected API endpoints without valid credentials. Such access could lead to unauthorized modifications of system settings and exposure of sensitive data. Path Traversal vulnerabilities are critical as they undermine authentication processes and may compromise both data integrity and confidentiality.

The vulnerability involves exploiting an API endpoint where the path normalization does not function as intended, letting attackers circumvent authentication. By crafting specific HTTP requests that manipulate URL paths, malicious users can exploit this logic flaw to gain unauthorized access. The vulnerable parameter is related to the improper handling of path segments like "../" in the URL path, which allows traversal to unauthorized paths. This technical flaw may be present in any OpenFlagr installations running version 1.1.18 or earlier. Remedies revolve around fixing the path normalization routine to disallow traversal and ensure proper authentication checks occur.

If exploited, this vulnerability may lead to significant repercussions, including unauthorized access to sensitive application configurations. Attackers could modify feature flags, potentially disabling crucial functionalities or altering application behavior maliciously. The exposure of sensitive configuration data, such as API keys or credentials, could result in broader system compromises. Exploiting this vulnerability undermines the access control mechanisms, potentially leading to data breaches or system integrity failures. Mitigation actions should thus be promptly implemented to prevent unauthorized exploits.

REFERENCES

Solution Advice
Remediation:
  • Immediately update OpenFlagr to a version newer than 1.1.18 to mitigate this vulnerability.
  • Implement robust input validation to disallow path traversal sequences such as "../" in API requests.
  • Enhance authentication mechanisms to ensure all endpoint requests undergo strict authorization checks.
  • Regularly review and audit middleware logic for potential security issues.
  • Ensure logging is enabled for unauthorized access attempts to improve detection and response.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.