
CVE-2026-103244 hits sgoudelis's ground-station, CVSS 9.8. During first-run setup, an unauthenticated attacker can call setup.restore over SocketIO to plant admin users and forged session tokens, then log in as administrator with zero credentials. VulnTracker recommends upgrading to ground-station 0.8.0 now, this is a complete application takeover with no login required. Details: http://vulntracker.io/cves/CVE-2026-103244 #CVE #InfoSec #AppSec

