CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-101067 - dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal

CVE ID :CVE-2026-101067
Published : Sept. 28, 2026, 12:30 p.m. | 56 minutes ago
Description :A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18825 - Origin validation error in the connect-xcors npm package

CVE ID :CVE-2026-18825
Published : Sept. 28, 2026, 12:32 p.m. | 54 minutes ago
Description :An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82326 - HTML Injection in Enocta Educational's Enocta Platform

CVE ID :CVE-2026-82326
Published : Sept. 28, 2026, 12:33 p.m. | 52 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue affects Enocta Platform: through 2026-09-28.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82323 - Improper Authorization in Enocta Educational's Enocta Platform

CVE ID :CVE-2026-82323
Published : Sept. 28, 2026, 12:36 p.m. | 50 minutes ago
Description :Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101292 - Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization

CVE ID :CVE-2026-101292
Published : Sept. 28, 2026, 12:44 p.m. | 42 minutes ago
Description :Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers () and no-argument constructors (()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101068 - dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal

CVE ID :CVE-2026-101068
Published : Sept. 28, 2026, 12:45 p.m. | 41 minutes ago
Description :A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59563 - HMAC Confirmation Token Unbinding in zscaler-mcp-server

CVE ID :CVE-2026-59563
Published : Sept. 28, 2026, 12:54 p.m. | 31 minutes ago
Description :Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101069 - dbgate Export databaseConnections.js exportModelSql path traversal

CVE ID :CVE-2026-101069
Published : Sept. 28, 2026, 1 p.m. | 26 minutes ago
Description :A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52748 - Missing authentication for backup functionality in Kaon AR2140X

CVE ID :CVE-2026-52748
Published : Sept. 28, 2026, 1:01 p.m. | 24 minutes ago
Description :The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.  This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-52749 - Improper Authentication in Kaon AR2140X

CVE ID :CVE-2026-52749
Published : Sept. 28, 2026, 1:01 p.m. | 24 minutes ago
Description :The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101077 - Netcore NR289-GE boa_temp process_request missing authentication

CVE ID :CVE-2026-101077
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101078 - deepseek-ai deepseek-harness Landlock Backend profiles.ts isolation

CVE ID :CVE-2026-101078
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101079 - agentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on untrusted inputs in a security decision

CVE ID :CVE-2026-101079
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a local position. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 2.8 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101080 - Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal

CVE ID :CVE-2026-101080
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version 4.6.0 is able to mitigate this issue. The identifier of the patch is ac0384edc9dbea3b226edefcf50613bd8509134f. You should upgrade the affected component.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101861 - Langflow Code Execution via eval() in Component Input Schema

CVE ID :CVE-2026-101861
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is converted into a LangChain tool via ComponentToolkit.get_tools(), including during custom component saves through the API, by interpolating options into a Literal type string that is passed directly to eval() without safe evaluation controls.
Severity: 4.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12342 - SailPoint IdentityIQ Improper Form Validation Vulnerability

CVE ID :CVE-2026-12342
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88804 - Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher

CVE ID :CVE-2026-88804
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88805 - Session Not Revoked Server-Side on Logout in Rancher

CVE ID :CVE-2026-88805
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88808 - Fleet agent copies downstream resources with cluster-admin privileges, allowing cross-namespace writes on downstream clusters

CVE ID :CVE-2026-88808
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :A vulnerability has been identified within Rancher Manager where the Fleet agent wrote resources to downstream clusters using its own cluster-admin credentials instead of the ServiceAccount pinned to the deployment. It affects multi-tenancy environments where different tenants share the same downstream clusters, for example different privileged or untrusted teams inside the same organization. This could lead to overwritten configuration files. This issue affected SUSE Rancher Fleet 0.16 before 0.16.2, 0.15 before 0.15.7, and 0.14 before 0.14.11.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-91154 - Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service

CVE ID :CVE-2026-91154
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93348 - Unsloth Zoo Code Injection via model_type in config.json

CVE ID :CVE-2026-93348
Published : Sept. 28, 2026, 4:17 p.m. | 1 hour, 9 minutes ago
Description :Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations without enforcing a character allowlist, allowing newlines and arbitrary Python source to survive normalization. Attackers can embed a newline in a nested model_type value within a malicious model's config.json to terminate the generated import statement and execute arbitrary Python code via exec() in unsloth_compile_transformers(), achieving remote code execution as the loading user when the model is loaded for training or inference.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...