Cenobe / Research
Research that follows the evidence.
Original vulnerability research, exploitation analysis, and lessons from the field.
10 published articles
Research
From Zero to Shell: Exploiting Default Secrets in CrafterCMS
Double misconfigurations in the default CrafterCMS installation result in a critical vulnerability that allows authentication bypass, leading to administrative access and RCE
Read articleFrom the archive
9 articles

Research
NP Insurance Case Study: Building Security Confidence Through Comprehensive Testing
We recently partnered with NP Insurance to enhance their cybersecurity posture through penetration testing and vulnerability assessments. To understand the impact of our engagement, we spoke with Stelios Anagnostakis, IT & Information Security Compliance Consultant at NP Insurance, who shared valuable insights about their experience and the transformation in their security approach.

Research
Redirect-based OAuth Token Exposure in Bitbucket Integrations
An OAuth redirection-based access token leak affecting users of ONA who authenticated using Bitbucket was discovered. The attack relies on several technical details across ONA, Bitbucket, and browser behavior.

Research
Our Research Story: Unauthenticated RCE in Ametys CMS 4.7.x
Our Research Story: Unauthenticated RCE in Ametys CMS 4.7.x

Research
The Truth Behind Apache Tomcat’s CVE-2025-24813: Why Exploitation Isn’t Simple
CVE-2025-24813 has been making headlines with a critical 9.8 CVSS score, raising concerns across the industry. But after diving deep into its internals, our R&D team came to a different conclusion: this vulnerability is far harder to exploit than it seems.

Research
Exploiting SAP Crystal Report’s Vulnerability in 2025
In 2020, SAP disclosed CVE-2020-6219, a deserialization-based Remote Code Execution (RCE) vulnerability in the Crystal Report Viewer. Fast forward to 2025, and we revisited this flaw developing a practical exploitation path that highlights just how dangerous it remains in real-world scenarios.

Research
CVE-2025-27407: Inside the Critical GraphQL-Ruby RCE Vulnerability
How a popular Ruby gem exposed thousands of applications to remote code execution. A technical analysis of the vulnerability that affected major platforms worldwide.

Research
How Gitpod Strengthened Its Security Posture with Cenobe
Learn how a collaborative security assessment approach helped Gitpod transform their vulnerability management and build greater confidence in their products.

Research
Critical vulnerability in EGroupware product leads to remote code execution - CVE-2026-27823
A critical authorization bypass in EGroupware allows attackers to achieve remote code execution through arbitrary file upload and file read primitives. We break down the vulnerability, exploitation chain, responsible disclosure process, and how it was fixed by the EGroupware team.

Research
We Found a Critical Flaw in One of the World's Most Trusted Security Tools
How our research team found a CVSS 9.3 authentication bypass in Coverity, and what happened next.