Stellar Cyber Security Advisories
Stellar Cyber publishes a security advisory for each vulnerability that is assigned a CVE identifier and resolved in a Stellar Cyber product release. Each advisory identifies the affected components, the release that contains the fix, and the action you must take.
Advisories are published after a fix is generally available. Stellar Cyber follows a coordinated disclosure process and works with the reporting party on publication timing.
To report a suspected vulnerability in a Stellar Cyber product, contact security@stellarcyber.ai.
Current Advisories
|
CVE ID |
Summary |
Affected Component |
Fixed In |
|---|---|---|---|
| CVE-2026-50319 | Missing authentication on the local control interface | Server Sensor (Windows and Linux) | 6.6.0 |
| CVE-2026-50320 | Insecure storage of sensor registration metadata | Server Sensor (Windows and Linux) | 6.6.0 |
CVE-2026-50319
| CVE ID | CVE-2026-50319 |
| Summary | A missing authentication vulnerability in the Stellar Cyber Server Sensor allows a local low-privileged user on the host to issue commands to a local control interface, resulting in loss of sensor availability and limited disclosure of sensor configuration metadata. The affected module is the aella_conf local control service. |
| Severity | CVSS v3.1 base score 6.1 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CWE-306: Missing Authentication for Critical Function |
| Affected Versions | Server Sensor for Windows and Linux, all releases through 6.5.x |
| Fixed In | 6.6.0 |
| Workarounds | None. Upgrade to a fixed release. |
| Action Required | Upgrade your Server Sensors to a fixed release. Upgrading the Stellar Cyber Platform alone does not remediate this issue. |
| Acknowledgement | Stellar Cyber thanks Angel Gabriel Gil Rojas, Jorge Felix Gonzalez Arias, and Andy Rafael Muñoz Capellán of Big 5 for reporting this issue. |
CVE-2026-50320
| CVE ID | CVE-2026-50320 |
| Summary | Insecure storage of sensor registration metadata in the Stellar Cyber Server Sensor allows a local attacker with file system access to recover the registration metadata. The file is encrypted using a key embedded in the sensor binary, so the encryption does not effectively protect its contents. The exposed data is limited to registration-time metadata (cloud manager address, one-time registration token, and expiration) and does not include reusable authentication credentials. The affected module is the token handling utility. |
| Severity | CVSS v3.1 base score 3.3 (Low) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CWE-922: Insecure Storage of Sensitive Information |
| Affected Versions | Server Sensor for Windows and Linux, all releases through 6.5.x |
| Fixed In | 6.6.0 |
| Workarounds | None. Upgrade to a fixed release. |
| Action Required | Upgrade your Server Sensors to a fixed release. Upgrading the Stellar Cyber Platform alone does not remediate this issue. |
| Acknowledgement | Stellar Cyber thanks Angel Gabriel Gil Rojas, Jorge Felix Gonzalez Arias, and Andy Rafael Muñoz Capellán of Big 5 for reporting this issue. |
Upgrading Your Sensors
The advisories on this page are resolved by upgrading your sensors. Upgrading the Stellar Cyber Platform does not upgrade your sensors.
Refer to the Stellar Cyber 6.6.0 Release Notes for the supported sensor upgrade paths.
