CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-46623 - OpenAM Account Takeover via Unverified Password Change in OAuth2 Module

CVE ID :CVE-2026-46623
Published : Sept. 15, 2026, 9:52 a.m. | 13 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating disabled accounts. The missing OAuth.removeRestrictedAccountUpdateAttributes filtering permits these credential and status fields to reach the account update. With account creation enabled, repeated OAuth login causes the default ldapService chain to accept the username as both identifier and password, allowing an unauthenticated attacker to take over the local account without interacting with the identity provider. The rewrite can be denied for usernames shorter than the configured minimum password length. This issue is fixed in version 16.1.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62263 - OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass

CVE ID :CVE-2026-62263
Published : Sept. 15, 2026, 9:52 a.m. | 13 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A pre-authentication attacker can supply a userHandle whose serialized graph has a valid AuthenticatorImpl root and a nested gadget class, causing readObject or readResolve execution before the cast and assertion verification when a usable gadget is on the classpath. This bypasses the incomplete remediation for the earlier WebAuthn deserialization vulnerability. This issue is fixed in version 16.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45051 - OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage

CVE ID :CVE-2026-45051
Published : Sept. 15, 2026, 9:53 a.m. | 12 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the WebAuthn flow to be reachable and an attacker to have previously written controlled data to that attribute through delegated administration, provisioning, directory access, legacy REST self-registration, or unsafe configuration. When those non-default conditions hold, the data is deserialized before assertion verification and can execute a classpath gadget in the application server process. This issue is fixed in version 16.1.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19515 - OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution

CVE ID :CVE-2026-19515
Published : Sept. 15, 2026, 9:53 a.m. | 12 minutes ago
Description :The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful exploitation of this vulnerability could lead to the execution of arbitrary OS commands on the system where the VS Code extension is running. The extent of the impact is dependent on the privileges of the user account under which VS Code is operating. Exploitation requires the user to grant workspace trust to the malicious project and subsequently trigger the unit test execution.
Severity: 7.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5802 - Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery

CVE ID :CVE-2025-5802
Published : Sept. 15, 2026, 9:53 a.m. | 12 minutes ago
Description :The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-13166 - Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery

CVE ID :CVE-2025-13166
Published : Sept. 15, 2026, 9:53 a.m. | 12 minutes ago
Description :The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62280 - OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page

CVE ID :CVE-2026-62280
Published : Sept. 15, 2026, 9:54 a.m. | 11 minutes ago
Description :Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an active OpenAM session to follow a crafted authorization link and execute JavaScript in the OpenAM origin, enabling session or cookie theft, CSRF-token disclosure, and actions with the victim's privileges. At least one registered OAuth2 client is required, but the attacker does not need to control that client. This issue is fixed in version 16.1.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92058 - Use-after-free in the Graphics component

CVE ID :CVE-2026-92058
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92059 - Incorrect boundary conditions in the DOM: Editor component

CVE ID :CVE-2026-92059
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92060 - Use-after-free in the Internationalization component

CVE ID :CVE-2026-92060
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92061 - Incorrect boundary conditions in the Security: Process Sandboxing component

CVE ID :CVE-2026-92061
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92062 - Privilege escalation in the Session Restore component

CVE ID :CVE-2026-92062
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92063 - Denial-of-service in the Audio/Video component

CVE ID :CVE-2026-92063
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92064 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92064
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92065 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92065
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92066 - Sandbox escape in the Profile Backup component

CVE ID :CVE-2026-92066
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92067 - Use-after-free in the Widget: Gtk component

CVE ID :CVE-2026-92067
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92068 - Site isolation issue in the Reader Mode component

CVE ID :CVE-2026-92068
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92069 - Spoofing issue in the DOM: Navigation component

CVE ID :CVE-2026-92069
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92070 - Information disclosure in the Networking component

CVE ID :CVE-2026-92070
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-92071 - Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

CVE ID :CVE-2026-92071
Published : Sept. 15, 2026, 1:17 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...