Skip to content
ThreatCluster

Critical Twonky Server Vulnerabilities Allow Authentication Bypass

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Security researchers at Rapid7 identified critical vulnerabilities in Twonky Server that allow attackers to bypass authentication mechanisms. An unprotected API endpoint can be exploited to leak encrypted admin passwords, potentially compromising user accounts. Users of Twonky Server are advised to take immediate action to secure their systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (3)