EN
en direct
cve

Archive complète

Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-59501CWE-284: Improper Access ControlAnalyse NVD en cours Élevée CVSS 8.2 13/08 CVE-2026-59503CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized ActorAnalyse NVD en cours Critique CVSS 9.1 13/08 CVE-2026-59504CWE-602: Client-Side Enforcement of Server-Side SecurityAnalyse NVD en cours Critique CVSS 9.1 13/08 CVE-2026-59505CWE-284: Improper Access ControlAnalyse NVD en cours Élevée CVSS 8.6 13/08 CVE-2026-59506CWE-306: Missing Authentication for Critical FunctionAnalyse NVD en cours Critique CVSS 9.3 13/08 CVE-2026-59507CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access ControlAnalyse NVD en cours Critique CVSS 9.3 13/08 CVE-2026-59714Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-59765SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud MetadataAnalyse NVD en cours Élevée CVSS 7.5 13/08 CVE-2026-61960Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. Élevée CVSS 7.1 13/08 CVE-2026-61962Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. Critique CVSS 10 13/08 CVE-2026-61965Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions. Élevée CVSS 7.1 13/08 CVE-2026-61966Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. Critique CVSS 9.3 13/08 CVE-2026-61967Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. Critique CVSS 9.8 13/08 CVE-2026-61969Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. Critique CVSS 9.3 13/08 CVE-2026-61974Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. Élevée CVSS 7.1 13/08 CVE-2026-61979Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. Élevée CVSS 8.1 13/08 CVE-2026-61980Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions. Élevée CVSS 7.5 13/08 CVE-2026-61984Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. Élevée CVSS 7.5 13/08 CVE-2026-63423During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.Analyse NVD en cours Élevée CVSS 7.8 13/08 CVE-2026-63424During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.Analyse NVD en cours Élevée CVSS 7.3 13/08 CVE-2026-63425During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.Analyse NVD en cours Élevée CVSS 7.8 13/08 CVE-2026-63426During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-6387A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.Analyse NVD en cours Élevée CVSS 7 13/08 CVE-2026-6464Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.Postgresql Élevée CVSS 8.1 13/08 CVE-2026-6471Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.Postgresql Élevée CVSS 7.2 13/08 CVE-2026-65580Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. Élevée CVSS 7.1 13/08 CVE-2026-65582Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. Élevée CVSS 7.7 13/08 CVE-2026-65934An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.  See vulnerability B-E10 in the related paper below.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-65935Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.Analyse NVD en cours Élevée CVSS 7.6 13/08 CVE-2026-66256** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Analyse NVD en cours Élevée CVSS 7.2 13/08 CVE-2026-66424Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. Critique CVSS 9.8 13/08 CVE-2026-66426Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. Élevée CVSS 7.1 13/08 CVE-2026-66429Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. Élevée CVSS 7.1 13/08 CVE-2026-66430Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. Élevée CVSS 8.5 13/08 CVE-2026-66431Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. Élevée CVSS 7.5 13/08 CVE-2026-66432Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions. Élevée CVSS 7.5 13/08 CVE-2026-66436Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. Critique CVSS 9.3 13/08 CVE-2026-66441Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. Élevée CVSS 7.5 13/08 CVE-2026-66443Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions. Élevée CVSS 7.5 13/08 CVE-2026-66446Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. Critique CVSS 9.3 13/08 CVE-2026-66449Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions. Élevée CVSS 7.1 13/08 CVE-2026-66450Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. Élevée CVSS 8.1 13/08 CVE-2026-66453Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. Critique CVSS 9.8 13/08 CVE-2026-66458Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. Critique CVSS 9.3 13/08 CVE-2026-66461Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. Élevée CVSS 7.5 13/08 CVE-2026-66462Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. Élevée CVSS 7.5 13/08 CVE-2026-66463Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. Élevée CVSS 7.5 13/08 CVE-2026-66465Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. Critique CVSS 9.8 13/08 CVE-2026-66466Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. Élevée CVSS 7.5 13/08 CVE-2026-66468Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. Élevée CVSS 7.1 13/08 CVE-2026-66469Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. Élevée CVSS 7.5 13/08 CVE-2026-66472Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. Critique CVSS 9.3 13/08 CVE-2026-66478Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. Critique CVSS 9.3 13/08 CVE-2026-66653Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. Élevée CVSS 8.1 13/08 CVE-2026-66655Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions. Élevée CVSS 7.1 13/08 CVE-2026-66656Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. Élevée CVSS 8.1 13/08 CVE-2026-66657Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. Élevée CVSS 8.1 13/08 CVE-2026-66658Subscriber SQL Injection in Reviewer <= 3.14.2 versions. Élevée CVSS 8.5 13/08 CVE-2026-66661Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. Élevée CVSS 7.7 13/08 CVE-2026-66691Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. Critique CVSS 9.8 13/08 CVE-2026-66697Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. Élevée CVSS 7.1 13/08 CVE-2026-66698Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. Élevée CVSS 7.1 13/08 CVE-2026-66700Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. Élevée CVSS 7.1 13/08 CVE-2026-66704Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. Élevée CVSS 7.2 13/08 CVE-2026-67614CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.Analyse NVD en cours Critique CVSS 9.8 13/08 CVE-2026-67986amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.Analyse NVD en cours Élevée CVSS 8.4 13/08 CVE-2026-67991crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.Analyse NVD en cours Élevée CVSS 7.5 13/08 CVE-2026-68451In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.Analyse NVD en cours Élevée CVSS 7.8 13/08 CVE-2026-68452In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.Analyse NVD en cours Élevée CVSS 7.8 13/08 CVE-2026-68453In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf lengthAnalyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-68454In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).Analyse NVD en cours Élevée CVSS 8.8 13/08 CVE-2026-70452rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.Analyse NVD en cours Élevée CVSS 7.4 13/08 CVE-2026-70453rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.Analyse NVD en cours Élevée CVSS 7.5 13/08 CVE-2026-70454rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.Analyse NVD en cours Élevée CVSS 8 13/08 CVE-2026-70455rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.Analyse NVD en cours Élevée CVSS 7.5 13/08 CVE-2026-70456rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.Analyse NVD en cours Élevée CVSS 8.2 13/08 CVE-2026-70458rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.Analyse NVD en cours Élevée CVSS 8.2 13/08 CVE-2026-70460rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.Analyse NVD en cours Élevée CVSS 8.1 13/08 CVE-2026-70461rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.Analyse NVD en cours Élevée CVSS 8.2 13/08 CVE-2026-70463rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.Analyse NVD en cours Élevée CVSS 8.1 13/08 CVE-2026-70464rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.Analyse NVD en cours Élevée CVSS 7.5 13/08 CVE-2026-72629Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the deployment stop and deployment update operations, allowing an active trained model deployment in another space to be stopped or to have its allocated resources altered.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-72630Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-72632Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-72642The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storage. A user with the privileges required to upload and deploy a trained model can craft a model that reads and writes memory outside the intended allocation. The result is heap corruption that crashes the inference process, and, with sufficient control over the heap layout, could allow arbitrary code execution in the context of that process.Analyse NVD en cours Élevée CVSS 8.8 13/08 CVE-2026-72643Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in different realms are treated as the same owner. This discloses the configuration and instructions of an agent the caller does not own, and allows that agent to be altered or removed.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-72658Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.Analyse NVD en cours Élevée CVSS 7.3 13/08 CVE-2026-72665Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live query privileges or the Elastic Defend response action privileges that normally govern those capabilities. Depending on the response action involved, this can result in disclosure of information from the affected hosts or in unauthorized changes to their state.Analyse NVD en cours Élevée CVSS 8.1 13/08 CVE-2026-72669The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered flow can also cause the owner's onboarding view to fail with a server error.Analyse NVD en cours Élevée CVSS 7.6 13/08 CVE-2026-72670A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read settings.The proxy configuration possibly contains proxy authentication credentials and private key material that they should not be authorized to view.Analyse NVD en cours Élevée CVSS 7.7 13/08 CVE-2026-72672The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account instead of the account of the requesting user. Only Kibana feature privileges are verified, and the caller's Elasticsearch index privileges are not. An authenticated user who holds Elastic Security feature privileges but no read access to the Elastic Defend event indices can therefore retrieve field values from that data, including process command line arguments, which commonly contain tokens, credentials, connection strings, and other sensitive operational detail from protected hosts.Analyse NVD en cours Élevée CVSS 7.7 13/08 CVE-2026-72675Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning functionality did not apply that filter, so operations issued from one space were carried out against the machine learning data of every space in the deployment.Analyse NVD en cours Élevée CVSS 7.1 13/08 CVE-2026-72677Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration is removed.Analyse NVD en cours Élevée CVSS 7.3 13/08 CVE-2026-72741Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, and certificates.Analyse NVD en cours Élevée CVSS 8.1 13/08 CVE-2026-72776AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.Analyse NVD en cours Critique CVSS 9.8 13/08 CVE-2026-72777Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata.Analyse NVD en cours Élevée CVSS 8.6 13/08 CVE-2026-72839filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.Analyse NVD en cours Critique CVSS 9.8 13/08 CVE-2026-72840OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.Analyse NVD en cours Élevée CVSS 8.8 13/08 CVE-2026-72841luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.Analyse NVD en cours Critique CVSS 9.9 13/08 CVE-2026-72842luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host.Analyse NVD en cours Critique CVSS 9.9 13/08
2801–2900 / 11286 CVE

Tapez au moins deux caractères.

naviguer ouvrir esc fermer