decolua disclosed and fixed CVE-2026-55500 in 9Router, a high-severity flaw affecting versions earlier than 0.4.80 that left the /api/settings/database endpoint insufficiently protected. The issue allowed database export and import operations that could expose stored credentials, API keys, OAuth tokens, and configuration data, while also enabling a complete database overwrite that could hand an attacker control over the application state.
The remediation adds re-authentication for database export and import by requiring the current dashboard password, except for requests using a CLI token, and updates the UI to prompt for that password before sensitive operations. The same security patch also introduced an SSRF guard for /v1/web/fetch to block requests to localhost, internal hostnames, private IPv4 ranges, and private or loopback IPv6 addresses, addressing a separate server-side request forgery risk referenced alongside the database protection fix.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for the 9Router database export/import vulnerability was updated with references, affected version information, and an SSVC assessment. The synopsis states the issue affects versions earlier than 0.4.80, enables credential theft and database takeover, and that GitHub published a security advisory while decolua fixed it in version 0.4.80.
A GitHub commit introduced a fix requiring the current dashboard password for `/api/settings/database` export and import requests, addressing the vulnerable unauthenticated access path. The same commit also added an SSRF guard for `/v1/web/fetch` and referenced advisory GHSA-qvfm-67h2-2qfx.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.