ZeroHour

CVE-2026-71809

niche

Authentication Bypass via Hardcoded Master Code in Siam Ordering 1.0.0

CVSS 3.1
8.1 high
EPSS
<1%p16
Published
()
Modified
AI analysis

Siam Ordering's server component (siam-server) version 1.0.0 contains a hardcoded master verification code (CWE-259) that acts as a universal authentication bypass. A remote, unauthenticated attacker who knows or recovers this embedded code can log in as any user, merchant, or administrator on an affected deployment. Successful exploitation gives full account takeover, including administrative control over the ordering platform and its merchant data. Any organization self-hosting siam-server 1.0.0 is affected. No public proof-of-concept exists and no exploitation has been observed, with EPSS estimating only a 0.2% chance of exploitation in the next 30 days.

What to do: If you run siam-server 1.0.0, assume the authentication layer is bypassable and restrict access (VPN or IP allowlisting) until a patched release is available from the project. Rotate all user, merchant, and administrator credentials and review authentication logs for logins that cannot be matched to legitimate sessions. Monitor the project's repository for a fix, since no patched version is indicated in the current data.

Affected
Siam Ordering siam-server1.0.0
Estimated exposure
nichelikely well under 1,000 self-hosted deployments (unknown; order of magnitude: tens to hundreds of sites) — Siam Ordering is a small, self-hosted open-source ordering platform with no published install counts or public exposure data, so the affected population is plausibly limited to a small number of self-hosted instances.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

Weakness
CWE-259
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.