External risk intelligence

Covenant SignalR Hub Missing Authentication Exposes Sensitive Data

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-92717

Covenant is a C2 (Command and Control) framework used by security professionals for red teaming and penetration testing. It is designed to be operated within isolated, highly controlled environments rather than being exposed as a public-facing service. Typical deployments are restricted to authorized internal infrastructure for team operations.

Missing Authentication

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in the Covenant framework that allows unauthenticated access to its operator API. This could enable unauthorized individuals to access sensitive information and system controls. The primary concern is to confirm if this technology is in use and if there is any exposure.

  • Unauthorized API access to sensitive data.
  • Confirms if this technology is in use.
  • Assess relevance and confirm exposure.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication by directly interacting with the Covenant SignalR hub without needing any prior access or credentials. This allows them to invoke a specific function that grants them a signed token. With this token, the attacker can then access the full operator API, gaining access to sensitive information and functionalities within the Covenant framework.

  • Unauthenticated network access required.
  • Invoking the CovenantHub SignalR hub.
  • Unauthorized access to operator API.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to gain full access to the Covenant operator API. This would enable them to access sensitive information and potentially control the framework's operations.

  • Operator API access.
  • Unauthenticated invocation of a SignalR hub.
  • Unauthorized access to grunts, credentials, and binaries.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Covenant, specifically affecting its SignalR hub, allows unauthenticated access to sensitive operator API functions if exploited. Technical leaders and security teams should first identify all instances of the affected technology within their environment. Subsequently, they must confirm the business criticality and reachability of each instance, identify the accountable system owner, and then prioritize remediation efforts based on the assessed risk and operational impact.

  • Identify and inventory affected systems.
  • Verify reachability and business criticality.
  • Plan risk-based remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Covenant and how is it typically used?

Covenant is a command and control (C2) framework built for red teaming and penetration testing exercises. Security professionals use it to simulate advanced threats, manage communication with compromised systems, and execute post-exploitation tasks. It is designed to function as an internal tool within highly controlled, isolated laboratory or testing environments rather than as a public-facing service.

What is the vulnerability in CVE-2026-92717?

This vulnerability is classified as Missing Authentication for Critical Function (CWE-306). It occurs because the CovenantHub SignalR hub lacks an authorization check. This technical oversight allows anyone to reach the hub and invoke specific functions without needing a password or existing session, effectively bypassing the security controls intended to protect the system.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by sending a network request directly to the CovenantHub SignalR hub. No prior credentials, specialized access, or user interaction are required to initiate this communication. If the hub is reachable, the attacker can invoke the CreateHttpListener function to receive a signed JWT token, which is then used to impersonate an authorized operator. The bug is not triggered by standard framework operations that utilize properly secured endpoints.

Do I need to worry if my Covenant instance is internal?

Halo Surface Signal indicates that Covenant is intended for isolated infrastructure, making it very unlikely to be exposed as a public-facing service. While internal deployments significantly reduce the likelihood of remote exploitation by unauthorized parties, you should still care if the software exists in your environment. If any instance is unintentionally reachable from a broader or untrusted network, the risk of unauthorized access to the operator API remains elevated.

How should I respond to CVE-2026-92717?

Start by identifying and creating an inventory of all Covenant instances running in your environment. Once identified, verify their network reachability and business criticality to understand the potential impact. Assign accountability for each instance to a system owner who can confirm whether the service is appropriately isolated. Finally, prioritize your remediation efforts based on these findings to ensure the framework is secured against unauthorized API access.

References