CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-59327 - Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations

CVE ID :CVE-2026-59327
Published : July 30, 2026, 6:25 a.m. | 1 hour, 20 minutes ago
Description :Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace metadata or, if the user marks the configuration as a shared file, directly into the project tree where it can be committed to version control. This secret is the sole credential protecting the DevTools remote restart/reload endpoint, which accepts and executes arbitrary class bytes on the target application. Anyone able to read the .launch file (via filesystem access, a workspace backup, or a shared VCS repository) can extract the secret and use it to achieve remote code execution against the associated Spring Boot application. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59328 - Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips

CVE ID :CVE-2026-59328
Published : July 30, 2026, 6:25 a.m. | 1 hour, 20 minutes ago
Description :Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-64635 - Veeam Service Provider Console Open Redirect to Account Takeover

CVE ID :CVE-2026-64635
Published : July 30, 2026, 6:25 a.m. | 1 hour, 20 minutes ago
Description :Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-13584 - Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol

CVE ID :CVE-2026-13584
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44090 - Missing authentication for MQTT Broker

CVE ID :CVE-2026-44090
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44091 - Creation of a new configuration by posting a malicious ID to MQTT

CVE ID :CVE-2026-44091
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44092 - Missing input validation / stripping of CRLF characters in SystemConfigManager

CVE ID :CVE-2026-44092
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44093 - Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script

CVE ID :CVE-2026-44093
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44094 - Fallback to second RAUC slot with default credentials

CVE ID :CVE-2026-44094
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44095 - Local Privilege Escalation via Network scripts

CVE ID :CVE-2026-44095
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44096 - udhcpc Privilege Escalation

CVE ID :CVE-2026-44096
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44097 - File Upload vulnerability

CVE ID :CVE-2026-44097
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44098 - OS Command Injection in OCPP Agent via charge_box_id

CVE ID :CVE-2026-44098
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44099 - Local Privilege Escalation via pppd password injection

CVE ID :CVE-2026-44099
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44100 - JupiCore charging point reconfiguration without auth

CVE ID :CVE-2026-44100
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44101 - OCPP reconfiguration vulnerability

CVE ID :CVE-2026-44101
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44102 - OCPP Firmware download is not properly locked

CVE ID :CVE-2026-44102
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44103 - JupiCore does not perform validation of firmware

CVE ID :CVE-2026-44103
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected device. This vulnerability could be used in chain with CVE-2026-44104.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44104 - ControllerAgent does not perform validation of firmware

CVE ID :CVE-2026-44104
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44105 - Cleartext password in logs

CVE ID :CVE-2026-44105
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-44106 - Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file

CVE ID :CVE-2026-44106
Published : July 30, 2026, 7:16 a.m. | 29 minutes ago
Description :A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...