A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher. | |
| Title | Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails | |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-27T03:14:21.055Z
Reserved: 2026-07-24T05:29:02.405Z
Link: CVE-2026-16895
No data.
Status : Received
Published: 2026-08-27T04:16:41.530
Modified: 2026-08-27T04:16:41.530
Link: CVE-2026-16895
No data.
OpenCVE Enrichment
Updated: 2026-08-27T05:30:07Z
Weaknesses