CVE-2026-92801: cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions

Published Sep 16, 2026
·
Updated

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.

Affected Software

1 affected component
cc-connect<=1.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade cc-connect to a version that resolves this vulnerability.

    Fixed in 1.5.0

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this bypass?

Deployments using cc-connect's Feishu integration are exposed when an attacker can trigger interactive card actions in a chat that has been admitted. The affected access control is the per-user allowlist; the issue does not indicate that access to arbitrary, non-admitted chats is gained.

2

What does an attacker need to exploit it?

An attacker needs the ability to trigger a Feishu interactive card callback in an admitted chat. No user interaction is required, and the listed attack vector is network-based with low attack complexity, but the attacker must have the low privileges needed to invoke the card action.

3

Are text-message commands also affected?

The issue specifically affects the onCardAction handler for Feishu interactive card callbacks. The description states that the text-message handler is protected by per-user access controls, so the documented bypass is limited to card actions.

4

How can I determine whether my deployment is affected?

Check whether you run cc-connect version 1.5.0 or earlier and use Feishu interactive cards in admitted chats. Affected behavior would allow a user who is not on the per-user allowlist to dispatch agent commands through a card action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203