CVE 10 CRITICAL

Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge_CVE-2026-2577

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hijack the WhatsApp session. This allows the attacker to send messages on behalf of the user, intercept all incoming messages and media in real-time, and capture authentication QR codes.

AI Analysis

Unauthenticated WhatsApp session hijack via WebSocket bridge

Basic Information

ID CVE-2026-2577
Source tenable
Published Feb 16, 2026 at 09:51

Affected Product

Vendor HKUDS
Product nanobot
Affected Versions HKUDS nanobot 0

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor HKUDS
Product Nanobot

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.