CVE-2026-39386Disclosure(m1k1o / neko)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance. The vulnerability has been patched in v3.0.11 and v3.1.2. If upgrading is not immediately possible, the following mitigations can reduce risk: Restrict access to trusted users only (avoid granting accounts to untrusted parties); ensure all user passwords are strong and only shared with trusted individuals; run the instance only when needed; avoid leaving it continuously exposed; place the instance behind authentication layers such as a reverse proxy with additional access controls; disable or restrict access to the /api/profile endpoint if feasible; and/or monitor for suspicious privilege changes or unexpected administrative actions. Note that these are temporary mitigations and do not fully eliminate the vulnerability. Upgrading is strongly recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-269CWE-284CWE-639CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • neko

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
neko

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-21: 3Mentions · 2026-04-28: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2104-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-213
Disclosure2General1
2026-04-281
Disclosure1
Full discourse4 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39386: CVE-2026-39386: Mass Assignment Privilege Escalation in Neko WebRTC Browser CVE-2026-39386 is a high-severity mass assignment vulnerability in the Neko virtual browser system. It permits any authenticated user to elevate their privileg... https://cvereports.com/reports/CVE-2026-39386

    Post summary

    The text discloses a high‑severity mass‑assignment privilege escalation bug in the Neko WebRTC Browser that allows authenticated users to elevate privileges, but it does not include a PoC, exploit code, patch, or evidence of active exploitation.

    0000030
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Neko, Self-service Privilege Escalation, #CVE-2026-39386 (High) https://dailycve.com/neko-self-service-privilege-escalation-cve-2026-39386-high/

    Post summary

    A concise announcement of a new high‑severity privilege escalation vulnerability (CVE‑2026‑39386) with no PoC, exploit, or mitigation details provided.

    0000029
    183 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-39386 Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immed… https://www.cve.org/CVERecord?id=CVE-2026-39386

    Post summary

    The post references CVE-2026-39386 affecting Neko’s WebRTC usage, but offers no concrete details on exploitation, patching, or technical specifics.

    0000086
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-39386 Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 … CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-39386 #Docker #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2026‑39386, provides basic technical details and a CVSS score, and links to a full analysis without mentioning PoC, exploit, or patches.

    000008
    124 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appm1k1oneko---

Explore more