PT-2026-23648 · Talishar · Talishar
Published
2026-03-06
·
Updated
2026-03-06
·
CVE-2026-28428
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Talishar versions prior to commit a9c218e
Description
Talishar is a fan-made Flesh and Blood project with an authentication bypass issue in its game endpoint validation logic. An unauthenticated attacker can perform authenticated game actions, including sending chat messages and submitting game inputs, by providing an empty
authKey parameter. The server-side validation uses a loose comparison, incorrectly accepting an empty string as a valid credential. This bypass occurs because the authentication mechanism can be circumvented without a valid token. The vulnerable endpoint is the game endpoint.Recommendations
Update Talishar to commit a9c218e or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Talishar