CVE-2026-56681 | decolua 9router up to 0.5.5 API Key Validation src/dashboardGuard.js isLocalRequest X-9r-Real-Ip improper authorization
A vulnerability marked as critical has been reported in decolua 9router up to 0.5.5. Affected is the function isLocalRequest of the file src/dashboardGuard.js of the component API Key Validation. This manipulation of the argument X-9r-Real-Ip causes improper authorization.
This vulnerability is tracked as CVE-2026-56681. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More