CVE tracker
370 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-15258 - Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter

CVE ID :CVE-2026-15258
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15381 - WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter

CVE ID :CVE-2026-15381
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16236 - Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload

CVE ID :CVE-2026-16236
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18452 - Rich Source|DMS+ (Non-Mobile) - Use of Hard-coded Credentials

CVE ID :CVE-2026-18452
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-8155 - BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR

CVE ID :CVE-2026-8155
Published : July 31, 2026, 7:16 a.m. | 36 minutes ago
Description :The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete other users' private messages.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65309 - Storage of passwords in a reversible format

CVE ID :CVE-2026-65309
Published : July 31, 2026, 7:17 a.m. | 35 minutes ago
Description :ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16105 - Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints

CVE ID :CVE-2026-16105
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18203 - Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes

CVE ID :CVE-2026-18203
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18206 - Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass

CVE ID :CVE-2026-18206
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18208 - Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim

CVE ID :CVE-2026-18208
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18209 - Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check

CVE ID :CVE-2026-18209
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18211 - Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains

CVE ID :CVE-2026-18211
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18214 - Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction

CVE ID :CVE-2026-18214
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18215 - Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant

CVE ID :CVE-2026-18215
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18217 - Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution

CVE ID :CVE-2026-18217
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
Severity: 3.4 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18218 - Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero

CVE ID :CVE-2026-18218
Published : July 31, 2026, 8:16 a.m. | 3 hours, 38 minutes ago
Description :A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65310 - Missing authentication and permissive CORS policy

CVE ID :CVE-2026-65310
Published : July 31, 2026, 9:16 a.m. | 2 hours, 37 minutes ago
Description :ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65311 - Missing authentication for logging-configuration endpoint

CVE ID :CVE-2026-65311
Published : July 31, 2026, 9:16 a.m. | 2 hours, 37 minutes ago
Description :The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authentication. A remote, unauthenticated attacker with network access to the service may suppress audit logging, potentially concealing other activity on the system.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65313 - Use of hard-coded VNC credentials in the engineering-workstation provisioning

CVE ID :CVE-2026-65313
Published : July 31, 2026, 9:16 a.m. | 2 hours, 37 minutes ago
Description :A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10079 - Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection

CVE ID :CVE-2026-10079
Published : July 31, 2026, 10:16 a.m. | 1 hour, 37 minutes ago
Description :A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11770 - 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check

CVE ID :CVE-2026-11770
Published : July 31, 2026, 10:16 a.m. | 1 hour, 37 minutes ago
Description :A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...