CVE-2026-28428
MEDIUMTalishar < a9c218efa37756c9e7eed056fbff6ee03f79aefc - Unauthenticated Authentication Bypass via Empty authKey Parameter
Title source: llmDescription
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talishar's game endpoint validation logic allows any unauthenticated attacker to perform authenticated game actions — including sending chat messages and submitting game inputs — by supplying an empty authKey parameter (authKey=). The server-side validation uses a loose comparison that accepts an empty string as a valid credential, while correctly rejecting non-empty but incorrect keys. This asymmetry means the authentication mechanism can be completely bypassed without knowing any valid token. This issue has been patched in commit a9c218e.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Talishar/Talishar/security/advisories/GHSA-2659-p579-wv83
Scores
CVSS v3
5.3
EPSS
0.0030
EPSS Percentile
21.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (2)
talishar/talishar
< 2026-02-22
Talishar/Talishar
< a9c218efa37756c9e7eed056fbff6ee03f79aefc
Published
Mar 06, 2026
Tracked Since
Mar 06, 2026