---
id: CVE-2026-103397
title: >-
  OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay
  requests, allowing unpaired room members to impersonate paired devices by
  spoofing the RelayMessage From field
summary: >-
  OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay
  requests, allowing unpaired room members to impersonate paired devices by
  spoofing the RelayMessage From field. Attackers who know the room code can
  join, read p…
severity: medium
cvss: 5.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-290
vendor: Liquid-co
product: OpenSave
affected:
  - OpenSave < 2.4.0-beta.1
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T15:22:28.530'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103397'
references:
  - url: 'https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Liquid-co/OpenSave'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Liquid-co/OpenSave/blob/v2.3.1/internal/p2p/wanclient_handlers.go#L268-L282
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Liquid-co/OpenSave/commit/2f2612b13233ac123e01a03cb3008c44bacaeae3
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/opensave-before-2.4.0-beta.1-authentication-bypass-via-spoofed-relay-sender
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T15:07:05.376Z'
---

## Overview

OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
