CVE-2026-33950Disclosure(signalk / signal_k_server)

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch signalk signal_k_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated attacker can gain full Administrator access to the SignalK server at any time, allowing them to modify sensitive vessel routing data, alter server configurations, and access restricted endpoints. This issue has been patched in version 2.24.0-beta.4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-288CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • signal_k_server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-02); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
signal_k_server

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1PoC Mentioned / Linked · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 104-0204-0304-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1Patch1
2026-04-031
Disclosure1
2026-04-041
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Signal K Server` is affected by a critical privilege escalation vulnerability (CVE-2026-33950) via admin role injection at `/enableSecurity`. Review endpoint access controls. #SignalK #InfoSec https://www.pulsepatch.io/posts/cve-2026-33950-signal-k-server-privilege-escalation

    Post summary

    A new privilege escalation vulnerability, CVE-2026-33950, is disclosed affecting Signal K Server, allowing admin role injection at /enableSecurity; no PoC, exploit, or patch information is included.

    0000048
    11 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33950 - Critical Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /en... https://www.thehackerwire.com/vulnerability/CVE-2026-33950/ https://t.co/xwHAID4UlD

    Post summary

    The post discloses a privilege escalation flaw (CVE‑2026‑33950) in Signal K Server, describing admin role injection as the attack vector, but contains no PoC, exploit code, or evidence of active exploitation.

    0000054
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33950: CRITICAL] Signal K Server pre-version 2.24.0-beta.4 had a privilege escalation vulnerability. Update to the latest version to patch the Admin Role Injection threat and secure sensitive data.#cve,CVE-2026-33950,#cybersecurity https://cvefind.com/CVE-2026-33950

    Post summary

    The post alerts that Signal K Server versions before 2.24.0‑beta.4 have a privilege escalation flaw (Admin Role Injection) and urges users to upgrade to the latest release for protection.

    0000054
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33950: sig... Unauthenticated admin takeover on marine navigation systems - one HTTP request turns you into captain of someone else's boat. #MaritimeSec #PrivEsc. https://zerodaysignal.com/vulnerability/CVE-2026-33950 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-33950, briefly describes a privilege‑escalation vulnerability, and links to a source that likely contains a PoC, but does not mention exploitation in the wild, patches, or false‑positive claims.

    0000037
    194 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appsignalksignal_k_server---
Appsignalksignal_k_server2.24.0--
Appsignalksignal_k_server2.24.0--
Appsignalksignal_k_server2.24.0--

Explore more