CVE-2026-49819Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a condition that is false on every fresh install — allowing an unauthenticated network-adjacent attacker to register the initial superuser account, receive a long-lived JWT, and pivot to root remote code execution at `backend/networking/wake.go:43` (`exec.CommandContext(ctx, "/bin/sh", "-c", wake_cmd)`). Version 5.4.0 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-269CWE-306CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-13: 4PoC Mentioned / Linked · 2026-08-13: 2Patch / Workaround · 2026-08-13: 2Technical Details · 2026-08-13: 308-13
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • HOL@HashgraphOnline
    Disclosure

    CVE-2026-49819: UpSnap 4.4.1 through 5.3.5 exposes POST /api/upsnap/init-superuser with no auth. On a fresh install, anyone on the network can claim the first superuser, get a long-lived JWT, and drop a command into wake_cmd that runs as root. Fixed in 5.4.0. https://hol.org/blog/cve-2026-49819-upsnap-initial-superuser-takeover-root-rce

    Post summary

    CVE‑2026‑49819 is a newly disclosed unauthenticated remote‑code‑execution flaw in UpSnap, with detailed technical details, a link to a probable PoC, and a fix released in version 5.4.0.

    01060828
    19.2K followersView on X
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 13, 2026 🔴 CRITICAL: CVE-2026-61967 (miniorange/miniorange_otp_verification) AAS 12.9 — exploit available 🔴 CRITICAL: postgresql/postgresql (10 CVEs) AAS 12.6 — exploit available 🔴 CRITICAL: CVE-2026-49819 (seriousm4x/upsnap) AAS 12.6 — exploit available 🔴 CRITICAL: flowiseai/flowise (3 CVEs) AAS 12.2 — PoC available 🔴 CRITICAL: CVE-2026-73656 (triggerdotdev/trigger.dev) AAS 12.2 — PoC available 36 vulnerabilities — CRITICAL: 16, HIGH: 20 Full bulletin: https://aretiq.ai/bulletins/2026-08-13/

    Post summary

    The bulletin details critical vulnerabilities with confirmed exploits and PoCs, emphasizing the urgency for defensive action.

    00000119
    227 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 🚨 Critical Vulnerability · 13 August 2026 🎯 UpSnap critical flaw can lead from unauthenticated access to root-level RCE A critical vulnerability tracked as CVE-2026-49819 has been disclosed in UpSnap, an open-source Wake-on-LAN web application. The flaw affects versions 4.4.1 through 5.3.5 and has a CVSS score of 9.8. On vulnerable fresh installations, an unauthenticated attacker could claim the initial administrator account. That access could ultimately be chained into remote code execution with root privileges. The issue has been fixed in UpSnap 5.4.0. 🔗 Source: CVE disclosure / UpSnap security research #UpSnap #RCE #CriticalVulnerability #OpenSource #CyberSecurity

    Post summary

    UpSnap CVE‑2026‑49819 is a critical unauthenticated RCE vulnerability affecting versions 4.4.1–5.3.5, now fixed in 5.4.0.

    0000047
    53 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-49819 UpSnap Privilege Escalation and RCE via Missing Authentication in init-superuser API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49819

    Post summary

    The text announces CVE-2026-49819, a privilege escalation and remote code execution issue in UpSnap’s init-superuser API caused by missing authentication, but provides no PoC, exploitation details, or patch information.

    00000126
    4.1K followersView on X

Explore more