CVE-2026-56847 | Node.js up to 22.23.1/24.18.0/26.5.0 Permission Model trace_events.createTracing.enable permission (WID-SEC-2026-2585)
A vulnerability marked as critical has been reported in Node.js up to 22.23.1/24.18.0/26.5.0. This issue affects the function trace_events.createTracing.enable of the component Permission Model. This manipulation causes permission…
A vulnerability marked as critical has been reported in Node.js up to 22.23.1/24.18.0/26.5.0. This issue affects the function trace_events.createTracing.enable of the component Permission Model. This manipulation causes permission issues.
The identification of this vulnerability is CVE-2026-56847. It is possible to initiate the attack remotely. There is no exploit available.
Verschlüsselung im Ruhezustand & Unveränderbare SIEM-Logs
Geschützt (KMS Envelope Encryption)
Angreifer penetrieren Perimeter und WAF ungehindert. Schicht 3 (Micro-Segmentierung & Port-Drop) bildet die entscheidende Stop-Linie zur Schadenseindämmung.
Analyse für CVE-2026-56847 auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Verwandte Schwachstellen (gleicher Hersteller)
CVE-2023-32002CVE-2023-32002 | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.
This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x.
Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.
CVSS 9.8
CVE-2022-35255CVE-2022-35255 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.
CVSS 9.1
CVE-2023-32006CVE-2023-32006 | The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.
This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x.
Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.
CVSS 8.8
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (CVE-2026-56847)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff: