External risk intelligence

TarsWeb Authentication Bypass via Spoofed X-Forwarded-For and UID Parameter

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-80349

TarsWeb is a centralized management and deployment console for microservices. As a web application providing service administration, configuration, and deployment capabilities, it is commonly deployed as an internet-facing or internal-facing administrative gateway, making it a likely target for external access in common real-world deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in TarsWeb, a microservices management console, allows unauthenticated access to sensitive administrative functions by exploiting how the system trusts incoming request headers. An attacker could bypass authentication to perform actions like managing users, configuring services, or uploading code. The main concern is confirming relevance and exposure.

  • Bypasses authentication for administrative functions.
  • Affects systems managing microservices.
  • Confirm relevance and exposure to leadership.

Attack Path

How an attacker could exploit the issue

An attacker can impersonate any user, including an administrator, by sending a request with a forged `X-Forwarded-For` header and a `uid` query parameter. This allows them to bypass authentication and access sensitive routes for user and role administration, service configuration, and package deployment.

  • No authentication required.
  • Triggered by forged headers and parameters.
  • Allows full administrative access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to bypass authentication and access administrative functions by forging specific request headers. When supported by the advisory's configuration, this could grant an attacker administrative privileges, enabling them to alter service configurations, manage users and roles, or deploy packages.

  • Unauthorized administrative access to the system.
  • Forged headers could bypass authentication checks.
  • Compromised service configuration and data integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in TarsWeb allows unauthenticated attackers to bypass authentication and gain administrator-level access by exploiting the handling of the `X-Forwarded-For` header and the `uid` query parameter. Application owners or platform teams are responsible for identifying deployments of TarsWeb, confirming their exposure and business criticality, and then coordinating remediation with the vendor.

  • Application owners should prioritize identifying TarsWeb instances.
  • Verify all TarsWeb instances and their network exposure.
  • Plan and coordinate vendor-provided fixes or workarounds.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is TarsWeb?

TarsWeb is a centralized management console designed for microservices architectures. It provides a graphical interface for teams to handle service deployment, configuration management, and user administration within a distributed system environment.

How does CVE-2026-80349 bypass authentication?

This vulnerability is an Authentication Bypass by Spoofing (CWE-290). The application incorrectly relies on a client-provided header to determine if a connection is trusted. By forging this header to mimic a local request and pairing it with a specific user ID parameter, an attacker tricks the system into granting them full administrative privileges without providing any actual credentials.

Do I need to do anything specific to trigger this bug?

Yes, you must craft a request that includes both a spoofed X-Forwarded-For header and a uid query parameter. Simply interacting with the application normally or without these specific, manipulated inputs will not trigger the authentication bypass, as the system requires both components to falsely identify the requester as a trusted local administrator.

Is my TarsWeb instance at risk?

According to Halo Surface Signal, TarsWeb is frequently deployed as an administrative gateway that is accessible either internally or via the internet. Because it manages critical infrastructure, any instance reachable by network traffic—especially those facing the public internet—is considered a likely target for this unauthorized access.

What steps should I take if I run TarsWeb?

Begin by identifying all active TarsWeb deployments in your environment and verifying their network reachability. Once identified, prioritize these systems for remediation. Consult the vendor's documentation for version 3.0.16, which corrects the logic error in how trusted headers and account identities are processed.

References