What is CVE-2026-66420?
CVE-2026-66420 is a vulnerability in MeshCentral 1.1.21 that allows unauthenticated remote attackers to bypass cross-site WebSocket hijacking protection and hijack administrator sessions. This is caused by an unconditional early return in the CheckWebServerOriginName() function in webserver.js. Users should update MeshCentral to the latest version immediately.
Azərbaycanca: CVE-2026-66420 MeshCentral 1.1.21 platformasında autentifikasiya olunmamış uzaqdan hücum edənlərə WebSocket hijacking müdafiəsini yan keçərək administrator sessiyalarını ələ keçirməyə imkan verən boşluqdur. Bu boşluq webserver.js faylındakı CheckWebServerOriginName() funksiyasındakı şərtsiz erkən geri dönüş səbəbindən baş verir. MeshCentral istifadəçiləri dərhal proqramı ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which version of MeshCentral is affected by CVE-2026-66420?
MeshCentral version 1.1.21 is affected by this vulnerability.
Which function in MeshCentral causes this vulnerability?
The vulnerability is caused by an unconditional early return in the CheckWebServerOriginName() function in webserver.js.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.