https://reddit.com/r/netsec/comments/1sahl4e/mongoose_preauth_rce_and_mtls_bypass_on_millions/: Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices
Published Apr 2, 2026
·Updated
Affected Software
1 affected component
Cesanta Mongoose<=7.20
Frequently Asked Questions
1
What is the severity of CVE-2026-5244?
CVE-2026-5244 is classified as a high severity vulnerability due to the heap-based overflow that can lead to remote code execution.
2
How do I fix CVE-2026-5244?
To fix CVE-2026-5244, update the Cesanta Mongoose network library to version 7.21 or higher.
3
What are the consequences of CVE-2026-5245?
CVE-2026-5245 can result in a stack-based overflow, potentially allowing attackers to execute arbitrary code on affected devices.
4
Is CVE-2026-5246 easy to exploit?
Yes, CVE-2026-5246 involves an authorization bypass that is considered trivially exploitable.
5
What versions of Cesanta Mongoose are affected by these vulnerabilities?
Cesanta Mongoose versions up to and including 7.20 are affected by CVE-2026-5244, CVE-2026-5245, and CVE-2026-5246.