CVE tracker
322 subscribers
4.53K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-10597 - ITPison|OMICARD EDM - Insecure Direct Object Reference

CVE ID :CVE-2026-10597
Published : June 4, 2026, 2:19 a.m. | 49 minutes ago
Description :OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-41011 - BOSH OS Command Injection

CVE ID :CVE-2026-41011
Published : June 4, 2026, 2:26 a.m. | 43 minutes ago
Description :PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No Shellwords.escape is applied. The Models::Package Sequel validation (VALID_ID = /^[-0-9A-Za-z_+.]+$/i) would reject the name, but in create_package (lines 74–79) the shell-out in save_package_source_blob runs before package.save, so validation fires too late. Affected versions: - BOSH: all versions prior to v282.1.12 (inclusive); fixed in v282.1.12 or later
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-41010 - BOSH Director: OS Command Injection

CVE ID :CVE-2026-41010
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into a shell string: Bosh::Common::Exec.sh("tar -C #{job_dir} -xf #{job_tgz} 2>&1", :on_error => :return). Bosh::Common::Exec.sh executes via %x{#{command}} (bosh-common/lib/bosh/common/exec.rb:53), i.e. /bin/sh -c, so any shell metacharacters in name are interpreted. FileUtils.mkdir_p(job_dir) on line 49 creates the literal directory (no shell) and succeeds even when the name contains $()/;, so execution reaches the sh call. Affected versions: - BOSH Director: all versions prior to v282.1.12 (inclusive); fixed in v282.1.12 or later
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-41283 - OpenStack Mistral Arbitrary Remote Code Execution

CVE ID :CVE-2026-41283
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44917 - OpenStack Ironic Local File Read via PXE Template

CVE ID :CVE-2026-44917
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48681 - OpenStack Ironic Directory Traversal File Overwrite

CVE ID :CVE-2026-48681
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49185 - Instruction Injection via FieldX MDM

CVE ID :CVE-2026-49185
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49186 - Lack of MQTT Broker Topic Access Control Lists

CVE ID :CVE-2026-49186
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10805 - Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend

CVE ID :CVE-2026-10805
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49187 - Hard-coded APK Resource Credentials & Scepters

CVE ID :CVE-2026-49187
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49188 - Elevated Root Command Execution via ai_cmd Sockets

CVE ID :CVE-2026-49188
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49189 - Broadcast Receiver Privilege Escalation

CVE ID :CVE-2026-49189
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50219 - Expat Use-After-Free Vulnerability

CVE ID :CVE-2026-50219
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49204 - Hard-coded AWS Cognito Testing Accounts

CVE ID :CVE-2026-49204
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50205 - Plaintext Log Credential Leakage

CVE ID :CVE-2026-50205
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50206 - VPN Command Injection Vulnerability

CVE ID :CVE-2026-50206
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3820 - Supermicro BMC's SMTP service contains a command injection vulnerability

CVE ID :CVE-2026-3820
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation. Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50207 - Local Modem Manipulation via Binder Interfaces

CVE ID :CVE-2026-50207
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50208 - Permissive TrustAllCerts TLS Verification

CVE ID :CVE-2026-50208
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50209 - MDM Server Registration Overriding

CVE ID :CVE-2026-50209
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50210 - Weak Static Cryptographic Initialization Vectors

CVE ID :CVE-2026-50210
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...