CVE Watchtower


← Back to CVE List

CVE-2026-35029NVD

Vulnerability Summary

### Impact

The `/config/update endpoint` does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to do the following:

- Modify proxy configuration and environment variables
- Register custom pass-through endpoint handlers pointing to attacker-controlled Python code, achieving remote code execution
- Read arbitrary server files by setting UI_LOGO_PATH and fetching via /get_image
- Take over other priveleged accounts by overwriting UI_USERNAME and UI_PASSWORD environment variables

### Patches

Fixed in v1.83.0. The endpoint now requires `proxy_admin` role.

### Workarounds

Restrict API key distribution. There is no configuration-level workaround.
Severity Level
HIGH
Published Date
Apr 3, 2026
Last Modified
May 6, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
19.38%Probability
Root Weakness (CWE)
N/A

External References