External risk intelligence

Northstar H2 Console Authentication Bypass Leads to Pre-Auth RCE

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-88391

The vulnerability involves an H2 database console in a quantitative trading platform. While this interface is typically intended for internal development or administrative use and is not designed to be public-facing, it is often unintentionally exposed or misconfigured in server deployments, making network reachability possible depending on the specific environment setup.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects the Northstar quantitative trading platform, allowing unauthenticated attackers to execute arbitrary system commands by exploiting an exposed H2 database console. If this system is accessible over the network, it presents a significant risk.

  • Unprotected database access allows command execution.
  • Critical system is exposed without authentication.
  • Confirm relevance; assess potential command execution risk.

Attack Path

How an attacker could exploit the issue

An attacker can gain unauthorized access to the H2 Console due to an incomplete authentication interceptor in the Northstar quantitative trading platform. By targeting the exposed `/h2-console` endpoint, an attacker can leverage the default credentials of the embedded H2 database to execute arbitrary system commands. This vulnerability allows for pre-authentication remote code execution, posing a significant risk to the system.

  • Network accessible, no authentication needed.
  • H2 Console endpoint is exposed.
  • Leads to arbitrary system command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated, network-accessible attacker to execute arbitrary system commands on the affected system. This is possible because the H2 database console, which is enabled by default, lacks authentication and uses default credentials. When this console is network-reachable, an attacker can exploit it to run commands, potentially leading to system compromise.

  • System commands and database access at risk.
  • Network-reachable H2 console with default credentials.
  • Arbitrary system command execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Northstar quantitative trading platform exposes an unauthenticated H2 console, allowing pre-authentication remote code execution. Security and platform teams should prioritize identifying all Northstar instances, confirming network reachability, and assessing business criticality. Once exposure is understood, engage the accountable application owner to plan a risk-based remediation strategy, which may involve vendor coordination or temporary risk reduction measures if immediate patching is not feasible.

  • Identify Northstar instances and exposure.
  • Confirm asset ownership and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Northstar platform?

Northstar is a quantitative trading platform used for financial analysis and automated trade execution. It relies on internal components like an embedded H2 database to manage data. This specific vulnerability involves the H2 Console, a web-based administrative interface typically used for database management, which is bundled within the application environment.

What does CWE-94 mean in the context of CVE-2026-88391?

CWE-94 refers to Improper Control of Generation of Code. For this CVE, it means the application inadvertently allows an attacker to inject and execute their own system-level commands. Because the database console lacks proper security, the system treats unauthorized input as legitimate instructions, enabling remote code execution.

How can an attacker trigger this vulnerability?

An attacker triggers this by reaching the H2 Console endpoint over the network without needing any login credentials. They use the database's default settings—specifically the 'sa' username with an empty password—to gain access. Note that requests routed through the protected /northstar/ path remain blocked; the bug specifically exists because the /h2-console path bypasses these security checks.

Is my Northstar instance at risk?

If your Northstar instance is reachable over a network, you are at higher risk. According to Halo Surface Signal, while the H2 Console is designed for administrative use and not intended to be public-facing, it is frequently misconfigured or accidentally exposed during deployment, making it reachable to unauthorized parties.

What should I do first to address CVE-2026-88391?

Start by identifying all deployed Northstar instances in your environment. Determine if the H2 Console is network-accessible and verify which systems are critical to your operations. Coordinate with your application owners to restrict access to this console or apply necessary updates provided by the vendor to close the authentication gap.

References