CVE-2023-37266 is a critical authentication bypass vulnerability affecting CasaOS versions prior to 0.4.4, allowing unauthenticated attackers to forge JSON Web Tokens (JWTs). This flaw enables unauthorized access to authenticated features and arbitrary root command execution on affected CasaOS instances. With a CVSS score of 9.8 (Critical), the attack requires no user interaction or privileges, making it easily exploitable with high impact on confidentiality, integrity, and availability. While not listed on KEV, a Nuclei template exists, and the vulnerability has garnered significant community discussion, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.