CVE-2026-49009 is a directory traversal vulnerability in Northern.tech Mender Server. According to the provided content, the issue affects Mender Server v4.1.0, v4.0.1, and earlier versions in the 4.0.x branch, and is fixed in v4.1.1 and v4.0.2. The vulnerability allows traversal outside the intended directory scope, which can permit access to files or resources not meant to be exposed. Specific vulnerable functions, request paths, or parameters are not provided in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository is minimal and centered on a single Nuclei template, CVE-2026-49009.yaml, plus a LICENSE and a long-form README. The exploit targets Northern.tech Mender Server and Mender Server Enterprise versions described as vulnerable to CVE-2026-49009, an authenticated path traversal in the single-file artifact generation API that can be turned into remote code execution. Because this is a Nuclei repository artifact, the main exploit logic is entirely in the YAML template. The template performs a two-step authenticated attack chain: first it sends a POST request to /api/management/v1/useradm/auth/login using Basic authentication to obtain a JWT from the response body; then it sends a multipart POST to /api/management/v1/deployments/artifacts/generate with type=single-file and a crafted JSON args field containing filename ../../../../usr/bin/mender-artifact and dest_dir /opt/mender/app. The uploaded file is a shell script payload that replaces the expected executable path. When the asynchronous create-artifact-worker later invokes /usr/bin/mender-artifact, the attacker-controlled script runs. The included payload is operational rather than purely diagnostic: it executes /usr/bin/id and redirects output to /tmp/.cve-2026-49009, providing a simple proof of code execution inside the worker container. Matchers verify successful authentication, extraction of a JWT, a successful artifact generation response, and the presence of a Location header. This makes the template intrusive and exploitative, not merely a passive detector. Repository structure is straightforward: the YAML file is the only code artifact and the effective entry point; README.md documents the vulnerability, attack flow, affected versions, and references, and also mentions additional PoC material, but no Python exploit source is actually present in the repository snapshot provided. Overall, the repository's purpose is to provide an authenticated Nuclei-based exploit/verification template for path traversal leading to container-level RCE in vulnerable Mender Server deployments.
Repository is a small standalone Python PoC for CVE-2026-49009 targeting Mender Server’s authenticated single-file artifact generation workflow. Structure is minimal: LICENSE, a detailed README describing the vulnerability and impact, and exploit.py containing the full exploit logic. The exploit authenticates to the Mender management API, obtains a token, constructs a malicious shell-script payload, and submits a multipart artifact-generation request to /api/management/v1/deployments/artifacts/generate. The key exploit primitive is attacker control over args.filename, set to ../../../../usr/bin/mender-artifact, which abuses path traversal to overwrite a trusted executable inside the artifact worker container. When the workflow later invokes mender-artifact, the attacker-controlled script runs an arbitrary user-supplied command inside the backend worker. The script supports command-line parameters for target URL, username, password, and command to execute; it disables TLS verification for lab/self-signed setups and extracts the workflow job ID from the HTTP Location header. Overall, this is a real authenticated RCE exploit, not merely a detector, with a hardcoded but user-customizable command-execution payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.