cve
Vulnerability watch Full archive
idvulnerabilityseveritypublished
CVE-2026-66875In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.NVD analysis in progress High CVSS 8.8 CVE-2026-67179Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.NVD analysis in progress High CVSS 7.8 CVE-2026-67180Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.NVD analysis in progress High CVSS 8.4 CVE-2026-6726An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.NVD analysis in progress High CVSS 7.9 CVE-2026-67558The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.NVD analysis in progress High CVSS 7.4 CVE-2026-67568The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.NVD analysis in progress Critical CVSS 9.1 CVE-2026-68067The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.NVD analysis in progress Critical CVSS 9.8 CVE-2026-68792Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68793Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68794Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68795Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68796Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68798Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68800Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68801Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68803Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68804Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68805Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68806Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68807Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68810Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68811Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68812Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68814Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68815Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68816Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68817Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-68819Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-68820Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows Ancillary Function Driver for WinSock Critical CVSS 7 CVE-2026-68821Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.Microsoft App Installer High CVSS 7.8 CVE-2026-69102MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token signed with the publicly known default secret, submit it to the /sign/login/jwt/trust endpoint, and obtain a fully authenticated admin session with access to SSO application configuration and downstream application secrets.NVD analysis in progress Critical CVSS 9.8 CVE-2026-69109A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.NVD analysis in progress High CVSS 7.5 CVE-2026-69119Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying ownership or access rights to the target project, enabling attackers with any valid GitHub token to invoke bare KV-store operations such as projects.Fetch and project.Delete against any project ID to achieve cross-tenant project takeover.NVD analysis in progress High CVSS 8.3 CVE-2026-69223Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF).
This issue affects Apache Allura: before 1.19.1.
Users are recommended to upgrade to version 1.19.1, which fixes the issue.Apache Allura Critical CVSS 9.1 CVE-2026-69278Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.Microsoft Visual Studio Code High CVSS 7.8 CVE-2026-69306Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.Microsoft Visual Studio Code High CVSS 8.2 CVE-2026-69320Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.Microsoft Visual Studio Code High CVSS 8.8 CVE-2026-70130Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-70304Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70306Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.Microsoft Sharepoint Server Critical CVSS 9.3 CVE-2026-70307Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-70311Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-70313Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.Microsoft 365 Apps High CVSS 7.8 CVE-2026-70321Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.Microsoft Sharepoint Server High CVSS 8.8 CVE-2026-70324Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server High CVSS 8.8 CVE-2026-70326Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server High CVSS 8.8 CVE-2026-70329Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.Microsoft 365 Apps High CVSS 8.8 CVE-2026-70330Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70335Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.Microsoft Visual Studio Code High CVSS 7.8 CVE-2026-70336Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.Microsoft Visual Studio Code High CVSS 8.8 CVE-2026-70337Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.Microsoft Powershell High CVSS 8.8 CVE-2026-70338Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.Microsoft Powershell High CVSS 7.8 CVE-2026-70340Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.Microsoft Azure Cyclecloud High CVSS 8.1 CVE-2026-70344Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70345Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70346Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70347Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7.8 CVE-2026-70354Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Microsoft Visual Studio 2022 High CVSS 7.8 CVE-2026-70355Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.Microsoft Sharepoint Server High CVSS 8.7 CVE-2026-71217A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.NVD analysis in progress High CVSS 7.5 CVE-2026-71290Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain.
Please note the classic version of HttpClient is not affected by this vulnerability.
Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.Apache Httpclient Critical CVSS 9.1 CVE-2026-71331Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-71362Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.NVD analysis in progress Critical CVSS 9.1 CVE-2026-71383is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.Adobe Coldfusion High CVSS 7.3 CVE-2026-71384is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Coldfusion Critical CVSS 9.6 CVE-2026-71386is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.Adobe Coldfusion High CVSS 8.8 CVE-2026-71387ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.Adobe Coldfusion High CVSS 8.8 CVE-2026-71398Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.Adobe Campaign Critical CVSS 10 CVE-2026-71467A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.NVD analysis in progress High CVSS 7.5 CVE-2026-71845A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.Redhat Advanced Cluster Management For Kubernetes High CVSS 7.7 CVE-2026-72533An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the authorization layer. Successful exploitation grants the attacker root-level access to the underlying Docker host.NVD analysis in progress High CVSS 8.8 CVE-2026-72534A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against the target group. An attacker can grant their provisioning token full IdP superuser access and lock out all existing administrators.NVD analysis in progress High CVSS 8.8 CVE-2026-72535A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscription data for any tenant without credentials.NVD analysis in progress High CVSS 8.6 CVE-2026-72536A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tenant without credentials.NVD analysis in progress High CVSS 8.6 CVE-2026-72537A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attacker can rewrite or delete any account, including the superuser, using only a limited provisioning credential.NVD analysis in progress High CVSS 8.8 CVE-2026-72538An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command execution on the Prefect server.NVD analysis in progress High CVSS 8.8 CVE-2026-72543An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials.NVD analysis in progress High CVSS 7.5 CVE-2026-72544An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.NVD analysis in progress High CVSS 7.5 CVE-2026-72545An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials.NVD analysis in progress High CVSS 7.5 CVE-2026-72546An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to other accounts via the postInviteAttendee endpoint. The endpoint loads the target event by ID without scoping the query to the authenticated organiser account. An attacker can modify event data and financial records across account boundaries.NVD analysis in progress High CVSS 7.1 CVE-2026-72547An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attendees into events belonging to other accounts via the postImportAttendee endpoint. The endpoint loads the target event by ID without verifying ownership against the requesting organiser account. An attacker can inject bulk attendee data into any event in the system regardless of account boundaries.NVD analysis in progress High CVSS 7.1 CVE-2026-72548An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system.NVD analysis in progress High CVSS 7.5 CVE-2026-72550An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.NVD analysis in progress Critical CVSS 9.8 CVE-2026-72551A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-list bypass. The sandbox allow-list permits functions that transitively invoke system(), enabling a developer to escape the sandbox and gain OS command execution on the server. An attacker with a Developer-role account can achieve full server compromise.NVD analysis in progress High CVSS 8.8 CVE-2026-72552A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints.NVD analysis in progress High CVSS 7.5 CVE-2026-72555A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account.NVD analysis in progress High CVSS 8.1 CVE-2026-72556A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that bypasses the permission check for all users. Any authenticated user can trigger filter-based OS command execution regardless of their assigned role.NVD analysis in progress High CVSS 8.8 CVE-2026-72557An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server.NVD analysis in progress High CVSS 8.8 CVE-2026-72558An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.NVD analysis in progress High CVSS 8.8 CVE-2026-72561A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users.NVD analysis in progress High CVSS 8.8 CVE-2026-72562An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents.NVD analysis in progress High CVSS 8.8 CVE-2026-72563A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. The endpoint performs no authorization check, and the Lead model has guarded set to an empty array making all columns mass-assignable. An attacker with any agent account can corrupt lead data across team boundaries.NVD analysis in progress High CVSS 8.1 CVE-2026-72595A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent account can modify, escalate, or corrupt tickets assigned to other teams.NVD analysis in progress High CVSS 8.1 CVE-2026-72596A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.NVD analysis in progress High CVSS 8.1 CVE-2026-72599An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.NVD analysis in progress Critical CVSS 9.8 CVE-2026-72600A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.NVD analysis in progress High CVSS 7.5 CVE-2026-72601A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.NVD analysis in progress High CVSS 7.5 CVE-2026-72602A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing without authentication, as WIKI_AUTH_MODE defaults to false. An attacker can enumerate sensitive directory contents on the host system.NVD analysis in progress High CVSS 7.5 CVE-2026-72603An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.NVD analysis in progress Critical CVSS 9.9 CVE-2026-72605A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.NVD analysis in progress High CVSS 7.5 3601–3700 / 11286 CVE