CVE-2026-31309
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/mysteriumnetwork/node/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31309.json, https://nvd.nist.gov/vuln/detail/CVE-2026-31309, https://github.com/mysteriumnetwork/node/commit/bc099fcaff59fee9c8a8f8e07ffff5b3c5df2bb9, https://github.com/sch8ill/CVE-2026-31309