CVE-2026-90505: vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as potentially affected?
Deployments of vvbbnn00 WARP-Clash-API at or before commit c7bf2360073959861219b422e51ae86411051b46 should be treated as potentially affected. The product does not use versioning, so affected and unaffected release information is unavailable.
What access would an attacker need?
An attacker can launch the attack remotely but requires low-level privileges. Exploitation is rated high complexity and reported as difficult.
Is exploitation only theoretical?
No. A public exploit has been reported and could be used, although exploitation is described as difficult.
Is maintainer support or a vendor fix available?
The vulnerability affects products no longer supported by the maintainer. The vendor was contacted before disclosure but did not respond, and no remediation information is provided.