CVE-2026-90504: WARP-Clash-API
- Severity
- 5.5 (MEDIUM)
- Vendor
- VVBBNN00
- Affected versions
- c7bf2360073959861219b422e51ae86411051b46
- Patch status
- Unknown
- Published
- 2026-09-13T10:16:54.093
- Modified
- 2026-09-13T10:16:54.093
Why it matters
Vulnerability requiring standard triage and vendor validation.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Treat internet-facing systems as higher priority.
Technical summary
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
View the official NVD record for CVE-2026-90504
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-90558 |
sngrep
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-90561 |
strapi PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-90562 |
LangBot PATCH
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-90647 |
ASE2000 V2 Communication Test Set
Reporter: CVE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-15451 |
MemberPress Corporate Accounts PATCH
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-90537 |
AVideo
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-90560 |
zstd-jni
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-90559 |
snappy-java
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-90668 |
UnrealIRCd PATCH
Reporter: CVE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-90770 |
spug
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-90774 |
rustypaste PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-90768 EXPLOITED |
CAPEv2
Reporter: DISCLOSURE
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-90553 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-90556 |
freeciv PATCH
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-90493 |
Internet Download Manager
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-90769 |
open-notebook PATCH
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-90772 |
amundsen-frontend
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-90651 |
Socket Firewall PATCH
Reporter: CVE
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-90678 |
HAProxy PATCH
Reporter: CVE
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-86406 |
User Registration & Membership PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-89080 |
Really Simple Security PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-90616 |
Product identification pending PATCH
Reporter: CVE
|
7.4
HIGH
|
VIEW RECORD |
| CVE-2026-80071 |
User Registration & Membership PATCH
Reporter: CONTACT
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-90555 |
vLLM PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-90648 |
wabt
Reporter: CVE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-90767 |
Froxlor PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-90536 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90538 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90539 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90541 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90543 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90547 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90548 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90549 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90550 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90551 |
AVideo
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90554 |
vLLM PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90557 |
Product identification pending
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90494 |
node-restify
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-90513 |
api-lambda-send-email-ses
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-10148 |
Booking for Appointments and Events Calendar – Amelia PATCH
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-90535 |
Flowise PATCH
Reporter: DISCLOSURE
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90771 |
joi
Reporter: DISCLOSURE
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90534 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-90533 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-90495 |
Feng Office
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90498 |
vhr
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90504 |
WARP-Clash-API
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90509 |
orion-visor
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90510 |
orion-visor
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90514 |
School Registration and Fee System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-90485 |
Uninstaller
Reporter: CNA
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-88764 |
Simple Membership PATCH
Reporter: CONTACT
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-90540 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90542 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90544 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90545 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90546 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90552 |
AVideo
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-90486 |
openstatus
Reporter: CNA
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-77773 |
Contact Form to Chat Apps | Click to Chat to Order PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-88995 |
Bookit — Booking & Appointment Calendar PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-80072 |
User Registration & Membership PATCH
Reporter: CONTACT
|
4.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-90679 |
Product identification pending
Reporter: CVE
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-88912 |
rtMedia for WordPress, BuddyPress and bbPress PATCH
Reporter: CONTACT
|
4.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-86407 |
User Registration & Membership PATCH
Reporter: CONTACT
|
3.7
LOW
|
VIEW RECORD |
| CVE-2026-79300 |
sesam PATCH
Reporter: CVE
|
3.5
LOW
|
VIEW RECORD |
| CVE-2026-90773 |
procs
Reporter: DISCLOSURE
|
2.4
LOW
|
VIEW RECORD |
| CVE-2026-90487 |
xxl-job
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90488 |
xxl-job
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90490 |
vhr
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90491 |
gsubs
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90492 |
web_robot
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90499 |
vhr
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90500 |
vhr
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90501 |
vhr
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90507 |
WARP-Clash-API
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90511 |
OnlineBooks
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-90489 |
xxl-job
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-90496 |
Feng Office
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-90497 |
Feng Office
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-90502 |
ServerStatus
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-90503 |
Ludashi
Reporter: CNA
|
1.8
LOW
|
VIEW RECORD |
| CVE-2026-90508 |
Ludashi
Reporter: CNA
|
1.8
LOW
|
VIEW RECORD |
| CVE-2026-90505 |
WARP-Clash-API
Reporter: CNA
|
1.3
LOW
|
VIEW RECORD |
| CVE-2026-90506 |
WARP-Clash-API
Reporter: CNA
|
1.3
LOW
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.