THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90504 (HIGH 7.3) — A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploi

[NVD] CVE-2026-90504 (HIGH 7.3) — A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploi

highnvdPublished 2026-09-13

CVE-2026-90504 CVSS: 7.3 HIGH Published: 2026-09-13T10:16:54.093

A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Co

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90504