CVE-2026-25060Patch(oplist / openlist)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch oplist openlist systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsecureSkipVerify setting is default to true in the DefaultConfig() function in internal/conf/config.go. This vulnerability enables Man-in-the-Middle (MitM) attacks by disabling TLS certificate verification, allowing attackers to intercept and manipulate all storage communications. Attackers can exploit this through network-level attacks like ARP spoofing, rogue Wi-Fi access points, or compromised internal network equipment to redirect traffic to malicious endpoints. Since certificate validation is skipped, the system will unknowingly establish encrypted connections with attacker-controlled servers, enabling full decryption, data theft, and manipulation of all storage operations without triggering any security warnings. This vulnerability is fixed in 4.1.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-599

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openlist

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openlist

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 102-0202-03
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-021
Patch1
2026-02-031
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25060 TLS Certificate Verification Bypass in OpenList Frontend Before 4.1.10 Enables MitM Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25060

    Post summary

    CVE-2026-25060 is a TLS certificate verification bypass in OpenList Frontend versions before 4.1.10, allowing Man‑in‑the‑Middle attacks.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25060 OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for all storage driver communications. The TlsInsec… https://www.cve.org/CVERecord?id=CVE-2026-25060

    Post summary

    The CVE-2026-25060 vulnerability in OpenList Frontend involves disabled certificate verification for storage driver communications before version 4.1.10, and the issue is resolved by updating to 4.1.10 or later.

    00000128
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoplistopenlist---

Explore more