CVE-2026-108549: CHENHG5 Cc-Connect
High severity, CVSS 8.1.
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
Affected products
- CHENHG5 Cc-Connect: up to and including 1.5.0
Published 2026-10-10. Last modified 2026-10-10.