FR
live
cve

Full archive

Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-59501CWE-284: Improper Access ControlNVD analysis in progress High CVSS 8.2 13/08 CVE-2026-59503CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized ActorNVD analysis in progress Critical CVSS 9.1 13/08 CVE-2026-59504CWE-602: Client-Side Enforcement of Server-Side SecurityNVD analysis in progress Critical CVSS 9.1 13/08 CVE-2026-59505CWE-284: Improper Access ControlNVD analysis in progress High CVSS 8.6 13/08 CVE-2026-59506CWE-306: Missing Authentication for Critical FunctionNVD analysis in progress Critical CVSS 9.3 13/08 CVE-2026-59507CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access ControlNVD analysis in progress Critical CVSS 9.3 13/08 CVE-2026-59714Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataNVD analysis in progress High CVSS 7.5 13/08 CVE-2026-61960Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. High CVSS 7.1 13/08 CVE-2026-61962Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. Critical CVSS 10 13/08 CVE-2026-61965Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. High CVSS 7.1 13/08 CVE-2026-61966Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. Critical CVSS 9.3 13/08 CVE-2026-61967Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. Critical CVSS 9.8 13/08 CVE-2026-61969Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. Critical CVSS 9.3 13/08 CVE-2026-61974Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. High CVSS 7.1 13/08 CVE-2026-61979Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. High CVSS 8.1 13/08 CVE-2026-61980Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. High CVSS 7.5 13/08 CVE-2026-61984Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. High CVSS 7.5 13/08 CVE-2026-63423During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.NVD analysis in progress High CVSS 7.8 13/08 CVE-2026-63424During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.NVD analysis in progress High CVSS 7.3 13/08 CVE-2026-63425During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.NVD analysis in progress High CVSS 7.8 13/08 CVE-2026-63426During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-6387A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.NVD analysis in progress High CVSS 7 13/08 CVE-2026-6464Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.Postgresql High CVSS 8.1 13/08 CVE-2026-6471Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.Postgresql High CVSS 7.2 13/08 CVE-2026-65580Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. High CVSS 7.1 13/08 CVE-2026-65582Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. High CVSS 7.7 13/08 CVE-2026-65934An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-65935Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.NVD analysis in progress High CVSS 7.6 13/08 CVE-2026-66256** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.NVD analysis in progress High CVSS 7.2 13/08 CVE-2026-66424Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. Critical CVSS 9.8 13/08 CVE-2026-66426Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. High CVSS 7.1 13/08 CVE-2026-66429Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. High CVSS 7.1 13/08 CVE-2026-66430Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. High CVSS 8.5 13/08 CVE-2026-66431Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. High CVSS 7.5 13/08 CVE-2026-66432Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. High CVSS 7.5 13/08 CVE-2026-66436Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. Critical CVSS 9.3 13/08 CVE-2026-66441Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. High CVSS 7.5 13/08 CVE-2026-66443Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. High CVSS 7.5 13/08 CVE-2026-66446Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. Critical CVSS 9.3 13/08 CVE-2026-66449Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. High CVSS 7.1 13/08 CVE-2026-66450Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. High CVSS 8.1 13/08 CVE-2026-66453Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. Critical CVSS 9.8 13/08 CVE-2026-66458Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. Critical CVSS 9.3 13/08 CVE-2026-66461Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. High CVSS 7.5 13/08 CVE-2026-66462Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. High CVSS 7.5 13/08 CVE-2026-66463Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. High CVSS 7.5 13/08 CVE-2026-66465Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. Critical CVSS 9.8 13/08 CVE-2026-66466Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. High CVSS 7.5 13/08 CVE-2026-66468Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. High CVSS 7.1 13/08 CVE-2026-66469Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. High CVSS 7.5 13/08 CVE-2026-66472Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. Critical CVSS 9.3 13/08 CVE-2026-66478Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. Critical CVSS 9.3 13/08 CVE-2026-66653Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. High CVSS 8.1 13/08 CVE-2026-66655Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. High CVSS 7.1 13/08 CVE-2026-66656Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. High CVSS 8.1 13/08 CVE-2026-66657Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. High CVSS 8.1 13/08 CVE-2026-66658Subscriber SQL Injection in Reviewer <= 3.14.2 versions. High CVSS 8.5 13/08 CVE-2026-66661Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. High CVSS 7.7 13/08 CVE-2026-66691Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. Critical CVSS 9.8 13/08 CVE-2026-66697Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. High CVSS 7.1 13/08 CVE-2026-66698Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. High CVSS 7.1 13/08 CVE-2026-66700Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. High CVSS 7.1 13/08 CVE-2026-66704Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. High CVSS 7.2 13/08 CVE-2026-67614CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.NVD analysis in progress Critical CVSS 9.8 13/08 CVE-2026-67986amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.NVD analysis in progress High CVSS 8.4 13/08 CVE-2026-67991crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.NVD analysis in progress High CVSS 7.5 13/08 CVE-2026-68451In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.NVD analysis in progress High CVSS 7.8 13/08 CVE-2026-68452In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.NVD analysis in progress High CVSS 7.8 13/08 CVE-2026-68453In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf lengthNVD analysis in progress High CVSS 7.1 13/08 CVE-2026-68454In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).NVD analysis in progress High CVSS 8.8 13/08 CVE-2026-70452rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.NVD analysis in progress High CVSS 7.4 13/08 CVE-2026-70453rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.NVD analysis in progress High CVSS 7.5 13/08 CVE-2026-70454rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.NVD analysis in progress High CVSS 8 13/08 CVE-2026-70455rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.NVD analysis in progress High CVSS 7.5 13/08 CVE-2026-70456rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.NVD analysis in progress High CVSS 8.2 13/08 CVE-2026-70458rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.NVD analysis in progress High CVSS 8.2 13/08 CVE-2026-70460rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.NVD analysis in progress High CVSS 8.1 13/08 CVE-2026-70461rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.NVD analysis in progress High CVSS 8.2 13/08 CVE-2026-70463rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.NVD analysis in progress High CVSS 8.1 13/08 CVE-2026-70464rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.NVD analysis in progress High CVSS 7.5 13/08 CVE-2026-72629Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-72630Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-72632Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-72642The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.NVD analysis in progress High CVSS 8.8 13/08 CVE-2026-72643Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-72658Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.NVD analysis in progress High CVSS 7.3 13/08 CVE-2026-72665Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.NVD analysis in progress High CVSS 8.1 13/08 CVE-2026-72669The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.NVD analysis in progress High CVSS 7.6 13/08 CVE-2026-72670A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.NVD analysis in progress High CVSS 7.7 13/08 CVE-2026-72672The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.NVD analysis in progress High CVSS 7.7 13/08 CVE-2026-72675Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.NVD analysis in progress High CVSS 7.1 13/08 CVE-2026-72677Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.NVD analysis in progress High CVSS 7.3 13/08 CVE-2026-72741Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.NVD analysis in progress High CVSS 8.1 13/08 CVE-2026-72776AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.NVD analysis in progress Critical CVSS 9.8 13/08 CVE-2026-72777Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata.NVD analysis in progress High CVSS 8.6 13/08 CVE-2026-72839filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.NVD analysis in progress Critical CVSS 9.8 13/08 CVE-2026-72840OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.NVD analysis in progress High CVSS 8.8 13/08 CVE-2026-72841luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.NVD analysis in progress Critical CVSS 9.9 13/08 CVE-2026-72842luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host.NVD analysis in progress Critical CVSS 9.9 13/08
2801–2900 / 11286 CVE

Type at least two characters.

navigate open esc dismiss