PT-2026-33880 · Neko · Neko

Published

2026-04-21

·

Updated

2026-06-01

·

CVE-2026-39386

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Neko versions 3.0.0 through 3.0.10 Neko versions 3.1.0 through 3.1.1
Description An issue allows any authenticated user to obtain full administrative control of the Neko instance, including member management, room settings, broadcast control, and session termination. This leads to a complete compromise of the instance. The flaw is associated with the '/api/profile' endpoint.
Recommendations Update versions 3.0.0 through 3.0.10 to 3.0.11. Update versions 3.1.0 through 3.1.1 to 3.1.2. Restrict access to trusted users only. Ensure all user passwords are strong. Run the instance only when needed and avoid continuous exposure. Place the instance behind authentication layers such as a reverse proxy with additional access controls. Disable or restrict access to the '/api/profile' endpoint. Monitor for suspicious privilege changes or unexpected administrative actions.

Fix

LPE

Improper Access Control

Improper Privilege Management

IDOR

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-39386
GHSA-2GW9-C2R2-F5QF
GO-2026-4960

Affected Products

Neko