
CVE-2026-49819: UpSnap 4.4.1 through 5.3.5 exposes POST /api/upsnap/init-superuser with no auth. On a fresh install, anyone on the network can claim the first superuser, get a long-lived JWT, and drop a command into wake_cmd that runs as root. Fixed in 5.4.0. https://hol.org/blog/cve-2026-49819-upsnap-initial-superuser-takeover-root-rce
Post summary
CVE‑2026‑49819 is a newly disclosed unauthenticated remote‑code‑execution flaw in UpSnap, with detailed technical details, a link to a probable PoC, and a fix released in version 5.4.0.



