Threat Advisory

GitHub Flaw Lets Authenticated Users Disable Global Authentication

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting 9router versions <= 0.5.2 have been identified in 9router, a high-risk vulnerability allowing authenticated authorization downgrade via mass assignment in the endpoint.

CVE-2026-56679 (CVSS 8.7 — Severity): An authenticated user can set security-critical fields that are not meant to be modifiable here — notably requireLogin. Setting requireLogin: false disables authentication for the whole application, exposing all protected routes to unauthenticated access.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting 9router versions <= 0.5.2 have been identified in 9router, a high-risk vulnerability allowing authenticated authorization downgrade via mass assignment in the endpoint.

CVE-2026-56679 (CVSS 8.7 — Severity): An authenticated user can set security-critical fields that are not meant to be modifiable here — notably requireLogin. Setting requireLogin: false disables authentication for the whole application, exposing all protected routes to unauthenticated access.[emaillocker id="1283"]

CVE-2026-5842 (CWE-285, pre-auth bypass on `/api`, patched in 0.3.75). This finding requires a valid authenticated session and abuses input handling, not missing authentication.

RECOMMENDATION:

We recommend you to update 9router to version 0.5.4.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu