References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/Nacos/Nacos%E6%9C%AA%E6%8E%88%E6%9D%83%E4%B8%8B%E8%BD%BD%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF.md https://www.birdy02.com/2024/09/23/0d731b35-a0fa-4a02-955f-d60f465384fd https://cn-sec.com/archives/3439312.html https://github.com/plbplbp/loudong001/blob/main/Nacos/Nacos%E6%9C%AA%E6%8E%88%E6%9D%83%E4%B8%8B%E8%BD%BD%E9%85%8D%E7%BD%AE%E4%BF%A1%E6%81%AF.md https://www.gksec.com/nacos_unauthorized.html https://blog.csdn.net/Kris__zhang/article/details/116044910 https://developer.aliyun.com/article/1518034 https://nvd.nist.gov/vuln/detail/CVE-2021-29441 https://www.acunetix.com/vulnerabilities/web/alibaba-nacos-authentication-bypass-cve-2021-29441/ https://pentest-tools.com/vulnerabilities-exploits/nacos-141-authentication-bypass_2164
Related VulnerabilitiesPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPoCnacos-v3-auth-scope-bypass: Nacos 3.x - Unauthenticated Admin TakeoverPoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCCVE-2020-10221: rConfig <= 3.9.4 - Authenticated OS Command InjectionPoCCVE-2026-56270: Flowise <= 3.0.13 - Unauthenticated OAuth Configuration DisclosurePoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCweb-config: Web Configuration File - DetectPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadPoCclaude-code-agents: Claude Code Subagent Configuration - ExposureKestra /api/v1/main/flows/configs 命令执行漏洞(CVE-2026-53576)PoC大华智慧园区综合管理平台 config_changePort SQL注入漏洞PoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCENacos /nacos/actuator 未授权访问漏洞