CVE-2026-70559

HIGH

Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-70559. PoCs published by codeb0ssx.

AI-analyzed exploit summary The repository contains no actual exploit code, technical details, or vulnerability analysis. It only includes a README with an image and a Telegram link to 'get the PoC,' which is a common social engineering tactic to lure researchers into external, potentially malicious downloads.

Description

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with no session or role check. Any remote unauthenticated caller who can reach the Dinky HTTP port (8888 by default) receives the full live system configuration (54 entries on a stock v1.2.5 install) with one parameterless GET. Only one credential field (sys.maven.settings.repositoryPassword) has a desensitization handler wired; the other credential-bearing fields (sys.env.settings.dinkyToken, sys.ldap.settings.userPassword, sys.resource.settings.oss.accessKey and secretKey, and sys.dolphinscheduler.settings.token) return in cleartext. A bare install leaks the shipped defaults, including the hardcoded dinkyToken efda1551-7958-4e0f-80a8-dfd107df3e38 and minioadmin/minioadmin OSS keys; once an operator configures LDAP, object storage, or DolphinScheduler through the Settings Center, those live third-party credentials leak from the same endpoint. Because dinkyToken is the sole gate on the sibling POST /download/uploadFromRsByLocal arbitrary file write, this disclosure defeats token rotation as a mitigation for that vulnerability. Affects Dinky v1.2.5 (the current release, 2025-11-05) and the development branch (dev HEAD 63b5a5a), where the affected code is byte-identical.

Exploits (1)

github SUSPICIOUS
by codeb0ssx · poc
https://github.com/codeb0ssx/CVE-2026-70559-PoC

The repository contains no actual exploit code, technical details, or vulnerability analysis. It only includes a README with an image and a Telegram link to 'get the PoC,' which is a common social engineering tactic to lure researchers into external, potentially malicious downloads.

Classification
Suspicious 99%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Aug 07, 2026 Full analysis →

References (3)

Core 3
Core References
Technical Description technical-description
https://github.com/DataLinkDC/dinky/issues/4567

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
DataLinkDC/Dinky < 1.2.5
Published Aug 06, 2026
Tracked Since Aug 07, 2026