CVE-2026-2967
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.49%
- CWE
- CWE-940
- Published
- 2026-02-23
- Last modified
- 2026-03-12
Affected products
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
- Cesanta Mongoose
Weakness type
Related vulnerabilities
- CVE-2026-85085 — The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged...
- CVE-2026-78685 — Le-yan|Medical Practice Management System - Remote Code Execution
- CVE-2026-73419 — NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
- CVE-2026-55660 — TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- CVE-2026-54106 — U.S. GAO EPDS and CBCA EDS network access control bypass
- CVE-2026-48745 — Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
- CVE-2026-44894 — Netty's Default QUIC token handler accepts any client-supplied token
- CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection