Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-104385 represents a critical authentication bypass vulnerability affecting Groundhogg versions 4.8.3 and earlier, allowing unauthenticated attackers to access sensitive data without proper credentials. Categorized as CWE-201 (Exposure of Sensitive Information to an Unauthorized Actor), this vulnerability exposes organizations using Groundhogg—a popular WordPress CRM platform—to direct data theft and compliance violations. The risk is particularly acute for businesses relying on Groundhogg to manage customer relationships, contact information, and potentially payment data, making this a high-impact issue despite not yet appearing in CISA's Known Exploited Vulnerabilities catalog.
While this CVE does not currently map to specific MITRE ATT&CK techniques, Casky.ai's 754 security skills powered by Claude's extended reasoning capabilities would detect the underlying attack patterns associated with reconnaissance and credential access phases. A practitioner investigating this vulnerability through Casky would observe skill findings related to T1592 (Gather Victim Identity Information) and T1078 (Valid Accounts) techniques, as attackers exploit the lack of authentication controls to enumerate and access sensitive data. The platform's analysis would highlight the absence of proper access controls and authentication mechanisms, enabling security teams to map remediation efforts against unauthorized data access patterns and prioritize patching efforts for Groundhogg installations before exploitation occurs at scale.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-104385. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation