What happened
A flaw in the authentication boundary of Acme Edge Gateway allows a remote unauthenticated actor to access administrative endpoints intended for authorized users. The issue stems from improper validation of session state before routing requests to privileged functionality.
Affected versions
Edge Gateway: ≤ 3.2.4 Fixed: 3.2.5.
Why it matters
Successful use can result in administrative access to the gateway, including configuration changes and service disruption. Internet-facing, centrally deployed gateways have the highest exposure.
Detection & mitigation
- Upgrade to Acme Edge Gateway 3.2.5 or later.
- Monitor for unusual administrative actions and configuration changes.
- Restrict administrative interfaces to trusted networks.
- Review gateway access logs for unauthenticated requests to administrative paths.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-2026-29711-poc0x4D31FMay 24, 2026CandidateCVE-Intel · infosec-research/Acme-Edge-CVE-2026-29711Authentication bypass demonstration for CVE-2026-29711BypassPHPHIGHAnalyzed★ 18⑂ 4EPSS 61.23%CVE data: NISTCode indexedUpdated 26 May 2026Tags: cve, proof-of-conceptinfosec-research2026-05-24CandidateSource timeline
Vendor advisory published
CVE record published by NVDView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Public PoC repository observedView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.