THREAT OPS › Threat News › [NVD] CVE-2026-90507 (MEDIUM 6.3) — A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to imp
[NVD] CVE-2026-90507 (MEDIUM 6.3) — A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to imp
CVE-2026-90507 CVSS: 6.3 MEDIUM Published: 2026-09-13T10:16:55.720
A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched re
Indicators of compromise
- c7bf2360073959861219b422e51ae86411051b46sha1
- CVE-2026-90507cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90507