CRITICAL 9.8 CVE-2026-77915 Published 24 Aug 2026

rConfig Core Admin Auth Bypass

Worried this affects one of your servers?

rConfig Core versions before 8.2.10 contain an authentication bypass vulnerability.

An unauthenticated attacker can self-register an account with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled.

Upon successful registration, the attacker's account is immediately authenticated with Admin-level access, allowing access to stored device credentials, user data, and API token issuance.

Reference: CVE-2026-77915 on NVD

← Back to Security News