CVE-2026-75329

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.

  • Published Aug 26, 2026
  • CVSS 9.8 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75329 at the National Vulnerability Database