CVE-2026-28806 | nerves-hub nerves_hub_web up to 2.3.x API Endpoint improper authorization (GHSA-f8fr-mccc-xvcx)
A vulnerability was found in nerves-hub nerves_hub_web up to 2.3.x. It has been classified as critical. Affected is an unknown function of the component API Endpoint. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-28806. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.