CVE-2026-3192 is a high-severity improper authentication vulnerability in Chia Blockchain 2.1.0, specifically within the RPC Credential Handler's _authenticate function in rpc_server_base.py. This flaw allows remote attackers to bypass authentication, potentially leading to full compromise of the affected system. While the attack complexity is high and exploitability is difficult, public exploit disclosure exists. Despite the vendor's stance that host security is the user's responsibility, the vulnerability carries a CVSS score of 8.1 (HIGH) and has not yet garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0CPE matchmatch criteria | cpe:2.3:a:chia:blockchain:2.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.