Stellar Cyber Security Advisories

Stellar Cyber publishes a security advisory for each vulnerability that is assigned a CVE identifier and resolved in a Stellar Cyber product release. Each advisory identifies the affected components, the release that contains the fix, and the action you must take.

Advisories are published after a fix is generally available. Stellar Cyber follows a coordinated disclosure process and works with the reporting party on publication timing.

To report a suspected vulnerability in a Stellar Cyber product, contact security@stellarcyber.ai.

Current Advisories

CVE ID

Summary

Affected Component

Fixed In

CVE-2026-50319 Missing authentication on the local control interface Server Sensor (Windows and Linux) 6.6.0
CVE-2026-50320 Insecure storage of sensor registration metadata Server Sensor (Windows and Linux) 6.6.0

CVE-2026-50319

CVE ID CVE-2026-50319
Summary A missing authentication vulnerability in the Stellar Cyber Server Sensor allows a local low-privileged user on the host to issue commands to a local control interface, resulting in loss of sensor availability and limited disclosure of sensor configuration metadata. The affected module is the aella_conf local control service.
Severity CVSS v3.1 base score 6.1 (Medium)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE-306: Missing Authentication for Critical Function
Affected Versions Server Sensor for Windows and Linux, all releases through 6.5.x
Fixed In 6.6.0
Workarounds None. Upgrade to a fixed release.
Action Required Upgrade your Server Sensors to a fixed release. Upgrading the Stellar Cyber Platform alone does not remediate this issue.
Acknowledgement Stellar Cyber thanks Angel Gabriel Gil Rojas, Jorge Felix Gonzalez Arias, and Andy Rafael Muñoz Capellán of Big 5 for reporting this issue.

CVE-2026-50320

CVE ID CVE-2026-50320
Summary Insecure storage of sensor registration metadata in the Stellar Cyber Server Sensor allows a local attacker with file system access to recover the registration metadata. The file is encrypted using a key embedded in the sensor binary, so the encryption does not effectively protect its contents. The exposed data is limited to registration-time metadata (cloud manager address, one-time registration token, and expiration) and does not include reusable authentication credentials. The affected module is the token handling utility.
Severity CVSS v3.1 base score 3.3 (Low)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-922: Insecure Storage of Sensitive Information
Affected Versions Server Sensor for Windows and Linux, all releases through 6.5.x
Fixed In 6.6.0
Workarounds None. Upgrade to a fixed release.
Action Required Upgrade your Server Sensors to a fixed release. Upgrading the Stellar Cyber Platform alone does not remediate this issue.
Acknowledgement Stellar Cyber thanks Angel Gabriel Gil Rojas, Jorge Felix Gonzalez Arias, and Andy Rafael Muñoz Capellán of Big 5 for reporting this issue.

Upgrading Your Sensors

The advisories on this page are resolved by upgrading your sensors. Upgrading the Stellar Cyber Platform does not upgrade your sensors.

Refer to the Stellar Cyber 6.6.0 Release Notes for the supported sensor upgrade paths.

See also: