Unrated
Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via CREATE ALIAS (pre-auth RCE).
Published 2026-10-05 · last modified 2026-10-05
← Get alerted the moment a CVE hits your gear — subscribe freeNcerio by BeyondNets · data from NVD, CISA KEV, EPSS.