CVE-2026-29023 impacts Keygraph Shannon, where a hard-coded API key in its router configuration allows network attackers to authenticate if the router is exposed. This vulnerability, rated 7.3 HIGH (CVSS:3.1/AV:N/AC:L), enables unauthenticated remote attackers to proxy requests, leading to unauthorized API usage and potential disclosure of proxied data. While a mitigation exists (commit 023cc95), there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| KeygraphHQ | Shannon | >= 0, < 023cc953db742602964b7826105278d15c28a420CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.