CVE-2026-59804
MEDIUMMidscene Bridge Server - Session Hijack via Unauthenticated WebSocket
Title source: cnaDescription
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active bridge sessions by opening a cross-origin WebSocket connection to the local Socket.IO server, which performs no Origin header validation and requires no authentication token. Attackers can connect from any web page visited by the victim to seize the single-client slot, intercept and inject automation commands, exfiltrate command-payload data, or unconditionally terminate the server by supplying the MIDSCENE_BRIDGE_SIGNAL_KILL query parameter.
References (4)
Core 4
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/web-infra-dev/midscene/issues/2752
Patch patch
Fix Commit
https://github.com/web-infra-dev/midscene/commit/86f4118d1d847041c63d79e347e08c87c3f1a882
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/midscene-bridge-server-session-hijack-via-unauthenticated-websocket
Scores
CVSS v3
6.8
EPSS
0.0021
EPSS Percentile
11.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-1385
CWE-306
Status
published
Products (2)
web-infra-dev/midscene
< 1.10.3
web-infra-dev/midscene
86f4118d1d847041c63d79e347e08c87c3f1a882
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026