CVE-2026-108549 - cc-connect through 1.5.0 Missing Authentication via MAX Webhook Sender Spoofing
CVE ID :CVE-2026-108549 Published : Oct. 10, 2026, 3:16 p.m. | 13 minutes ago Description :cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is...