CVE tracker
387 subscribers
5.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-84115 - Cleo Harmony JWT Refresh Token connections privileges management

CVE ID :CVE-2026-84115
Published : Sept. 1, 2026, 3:17 p.m. | 51 minutes ago
Description :A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected component.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84233 - Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames

CVE ID :CVE-2026-84233
Published : Sept. 1, 2026, 3:17 p.m. | 51 minutes ago
Description :A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84201 - appium-mcp-server through 0.1.61 Path Traversal in write_file and write_files_batch

CVE ID :CVE-2026-84201
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory segments to overwrite arbitrary files with the server user's privileges, including shell profiles and configuration files in the home directory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84202 - ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading

CVE ID :CVE-2026-84202
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84203 - Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change

CVE ID :CVE-2026-84203
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84204 - GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval

CVE ID :CVE-2026-84204
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84205 - GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3 Revision Retrieval

CVE ID :CVE-2026-84205
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a page identifier they can access with an arbitrary revision identifier to read revision content from pages they lack permission to view.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84232 - Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content

CVE ID :CVE-2026-84232
Published : Sept. 1, 2026, 3:18 p.m. | 49 minutes ago
Description :A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using local filesystem storage. An authenticated user or attacker with content upload permissions can upload a specially crafted HTML or SVG file containing JavaScript, which executes in the browser of any user who visits the file URL, resulting in stored cross-site scripting (XSS) in the context of the host application.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84206 - Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore

CVE ID :CVE-2026-84206
Published : Sept. 1, 2026, 3:19 p.m. | 49 minutes ago
Description :Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to undo administrator deletions and bypass intended permission separation.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84207 - Heym before 0.0.98 SSRF via WebSocket endpoints

CVE ID :CVE-2026-84207
Published : Sept. 1, 2026, 3:19 p.m. | 49 minutes ago
Description :Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach internal services and read responses from the WebSocket Trigger node.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84267 - Gvfs: sftp: uninitialized heap disclosure in read_string()

CVE ID :CVE-2026-84267
Published : Sept. 1, 2026, 3:19 p.m. | 49 minutes ago
Description :A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84269 - Gvfs: afp: heap-based buffer overflow in dsi read path

CVE ID :CVE-2026-84269
Published : Sept. 1, 2026, 3:19 p.m. | 49 minutes ago
Description :A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84270 - Gvfs: mtp: out-of-bounds read in do_read()

CVE ID :CVE-2026-84270
Published : Sept. 1, 2026, 3:19 p.m. | 49 minutes ago
Description :A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-79682 - Dell PowerStore Command Injection Vulnerability

CVE ID :CVE-2026-79682
Published : Sept. 1, 2026, 3:30 p.m. | 38 minutes ago
Description :Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10195 - FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting

CVE ID :CVE-2026-10195
Published : Sept. 1, 2026, 3:30 p.m. | 37 minutes ago
Description :The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary commands on the underlying server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49329 - Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints

CVE ID :CVE-2026-49329
Published : Sept. 1, 2026, 3:30 p.m. | 37 minutes ago
Description :A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73725 - Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networking Fabric Composer

CVE ID :CVE-2026-73725
Published : Sept. 1, 2026, 7:47 p.m. | 22 minutes ago
Description :A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges, leading to a complete compromise of the affected host.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73726 - Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative Access

CVE ID :CVE-2026-73726
Published : Sept. 1, 2026, 7:47 p.m. | 22 minutes ago
Description :A vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer that could potentially allow an unauthenticated adjacent actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative access, modify system configurations, and access or manipulate sensitive data.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73727 - Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API

CVE ID :CVE-2026-73727
Published : Sept. 1, 2026, 7:47 p.m. | 22 minutes ago
Description :Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73728 - Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer API

CVE ID :CVE-2026-73728
Published : Sept. 1, 2026, 7:47 p.m. | 22 minutes ago
Description :Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73729 - Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer

CVE ID :CVE-2026-73729
Published : Sept. 1, 2026, 7:47 p.m. | 22 minutes ago
Description :A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...