A logic vulnerability
Medium5.1CVE-2026-16895 · Published Aug 27, 2026 · updated Aug 28, 2026
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set, the application resets the internal state flag msf.auth_initialized to false. The ApiToken Warden authentication strategy misinterprets this false value as an indicator that authentication is not initialized or required, thereby granting unauthenticated local access to the JSON-RPC request dispatcher.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Metasploit-framework Product | < 6.5.2 | 6.5.2 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-305
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | Rapid7 Velociraptor: code injection | High7.7 | 0.77.2 |
| Sep 10 | Rapid7 Velociraptor: insecure permissions | Critical9.9 | 0.77.2 |
| Aug 24 | Rapid7 Velociraptor: code injection | High8.9 | 0.77.2 |
| Aug 18 | Rapid7 Velociraptor: cross-site scripting | High8.1 | 0.77.2 |
| Aug 12 | A rogue Velociraptor client can upload a malformed sparse file such | Low3.5 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: improper authorization | Medium6.5 | 0.77.2 |