CVE-2026-33950 is a critical privilege escalation vulnerability affecting Signal K Server versions prior to 2.24.0-beta.4, a server application running on boat central hubs. Rated 9.4 CVSS, this flaw allows an unauthenticated attacker to gain full Administrator access by injecting an admin role via the /enableSecurity endpoint. This enables modification of sensitive vessel routing data, alteration of server configurations, and access to restricted endpoints. There is currently no evidence of active exploitation, nor are public exploit tools available, though it has received minor community discussion. Organizations using affected versions should update to 2.24.0-beta.4 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.24.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* | ||
2.24.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.24.0:beta1:*:*:*:*:*:* | ||
2.24.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.24.0:beta2:*:*:*:*:*:* | ||
2.24.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.24.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.