THREAT OPS › Threat News › [NVD] CVE-2026-90504 (HIGH 7.3) — A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploi
[NVD] CVE-2026-90504 (HIGH 7.3) — A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploi
CVE-2026-90504 CVSS: 7.3 HIGH Published: 2026-09-13T10:16:54.093
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Co
Indicators of compromise
- c7bf2360073959861219b422e51ae86411051b46sha1
- CVE-2026-90504cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90504