Nacos Auth Bypass & Forged JWT Admin Account Insertion
This rule detects potentially malicious HTTP requests targeting Alibaba Nacos services. It specifically identifies requests that include 'accesstoken' parameters when accessing sensitive endpoints such as user management, login, or configuration modification paths. This pattern is commonly associated with unauthorized attempts to leverage known Nacos vulnerabilities for credential access or configuration manipulation.
Cortex XDR

