CVE ID :CVE-2026-8890 Published : May 26, 2026, 7:16 p.m. | 1ย hour, 8ย minutes ago Description :code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP header. The middleware in middleware.ts skips identity header generation when an Auth-Key head
code100x Mobile API
Exploit
CVE-2026-8890
MITRE CVE High
Refer to CVE-2026-8890 NVD advisory