CVE-2026-88391: Dromara Northstar vulnerability
Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via CREATE ALIAS (pre-auth RCE).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Northstar versions 9.1.1 and earlier are exposed if an attacker can reach the application's /h2-console endpoint over the network. The endpoint is outside the /northstar/** path protected by the authentication interceptor.
What does an attacker need to exploit this issue?
No authentication is required. A network-reachable attacker can access the H2 Console using the embedded database's default sa account with an empty password, then use CREATE ALIAS to execute system commands.
Are default credentials involved?
Yes. The embedded H2 database uses the default sa username with an empty password, enabling unauthenticated console access when /h2-console is reachable.