CVE tracker
393 subscribers
5.78K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-93474 - Monta monta.app Insufficiently Protected Credentials

CVE ID :CVE-2026-93474
Published : Oct. 2, 2026, 9:27 p.m. | 20 minutes ago
Description :Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97212 - Monta monta.app Insufficient Session Expiration

CVE ID :CVE-2026-97212
Published : Oct. 2, 2026, 9:30 p.m. | 17 minutes ago
Description :The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97363 - Monta monta.app Improper Restriction of Excessive Authentication Attempts

CVE ID :CVE-2026-97363
Published : Oct. 2, 2026, 9:32 p.m. | 15 minutes ago
Description :The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105043 - MathWorks Simulink Arbitrary Code Execution Vulnerability

CVE ID :CVE-2026-105043
Published : Oct. 2, 2026, 9:34 p.m. | 13 minutes ago
Description :MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code execution.
Severity: 3.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-95102 - Monta monta.app Missing Authentication for Critical Function

CVE ID :CVE-2026-95102
Published : Oct. 2, 2026, 9:34 p.m. | 13 minutes ago
Description :WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94591 - Armatura LLC Armatura One Use of Hard-coded Cryptographic Key

CVE ID :CVE-2026-94591
Published : Oct. 2, 2026, 10:16 p.m. | 3 hours, 33 minutes ago
Description :Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94592 - Armatura LLC Armatura One Use of Hard-coded Credentials

CVE ID :CVE-2026-94592
Published : Oct. 2, 2026, 10:16 p.m. | 3 hours, 33 minutes ago
Description :Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94593 - Armatura LLC Armatura One Insertion of Sensitive Information into Log File

CVE ID :CVE-2026-94593
Published : Oct. 2, 2026, 10:16 p.m. | 3 hours, 33 minutes ago
Description :Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-94594 - Armatura LLC Armatura One Insertion of Sensitive Information into Log File

CVE ID :CVE-2026-94594
Published : Oct. 2, 2026, 10:16 p.m. | 3 hours, 33 minutes ago
Description :Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105048 - Zilliz Attu Playground Server-Side Request Forgery

CVE ID :CVE-2026-105048
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).
Severity: 4.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105049 - Zilliz Attu Server-Side Request Forgery Vulnerability

CVE ID :CVE-2026-105049
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105050 - PeaZip OS Command Injection Vulnerability

CVE ID :CVE-2026-105050
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105051 - Denuvo Anti-Tamper Hypervisor Detection Bypass

CVE ID :CVE-2026-105051
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Severity: 1.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84411 - MikroTik RouterOS Integer Underflow

CVE ID :CVE-2026-84411
Published : Oct. 2, 2026, 11:16 p.m. | 2 hours, 33 minutes ago
Description :The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73802 - Gitea act_runner Container Sandbox Escape Vulnerability

CVE ID :CVE-2026-73802
Published : Oct. 2, 2026, 11:18 p.m. | 2 hours, 32 minutes ago
Description :### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security profile overrides from workflow YAML are preserved in the final HostConfig. A workflow author can enter host PID/IPC namespaces and execute commands on the runner host as root. ### Details Source-to-sink path in act_runner: - `ContainerSpec.Options` accepts workflow YAML `container.options` - `RunContext.options()` appends workflow options to runner-level container options - Job container is created with `Privileged: rc.Config.Privileged` but also with `Options: rc.options(ctx)` - `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig - When privileged mode is disabled, only `copts.privileged` is forced false - `sanitizeConfig()` only filters `Binds` and `Mounts` - Preserved dangerous HostConfig fields: ```text Privileged=false PidMode=host IpcMode=host CapAdd=["ALL"] SecurityOpt=["seccomp=unconfined","apparmor=unconfined"] ``` Attacker workflow YAML: ```yaml jobs: breakout: runs-on: ubuntu-latest container: image: ubuntu:22.04 options: >- --pid=host --ipc=host --cap-add=ALL --security-opt seccomp=unconfined --security-opt apparmor=unconfined steps: - name: host namespace marker run: | nsenter -t 1 -m -u -i -n -p -- sh -c "id > /tmp/marker" ``` ### Impact An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can: - Enter host PID, IPC, and mount namespaces - Execute arbitrary commands as root on the runner host - Access runner host secrets, deployment credentials, and environment variables - Pivot to adjacent jobs running on the same runner - Access internal build infrastructure reachable from the runner host Critical severity for shared runners where untrusted users can trigger workflows. High severity for single-tenant runners with privileged mode explicitly disabled as a security control. ### Fix Direction Treat `container.options` as untrusted input. Reject or strip when privileged mode is disabled: - Host namespaces: `--pid=host`, `--ipc=host`, `--uts=host`, `--network=host` - Capability expansion: `--cap-add ALL`, `--cap-add SYS_ADMIN` - Security overrides: `--security-opt seccomp=unconfined`, `--security-opt apparmor=unconfined` - Device access: `--device`, `--device-cgroup-rule` - Volume inheritance: `--volumes-from` - Runtime controls: `--runtime`, `--cgroup-parent`
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104433 - Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString

CVE ID :CVE-2026-104433
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by sending a zero-length handshake frame. Attackers can connect to the handshake port listening on all interfaces and send an eight-byte frame to terminate the hosting process, such as an SGLang inference server.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104474 - OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update

CVE ID :CVE-2026-104474
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh runs as root on the next update.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104475 - IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload

CVE ID :CVE-2026-104475
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can upload JavaScript-laden SVGs via the profile update or settings upload endpoints, which execute in victims' browsers when served from the /public route.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104476 - Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive

CVE ID :CVE-2026-104476
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104477 - Showdown through 2.1.0 XSS via unescaped quote in href and src attributes

CVE ID :CVE-2026-104477
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104478 - Formwork before 2.3.13 Path Traversal via BackupController Download and Delete

CVE ID :CVE-2026-104478
Published : Oct. 3, 2026, 12:16 a.m. | 1 hour, 33 minutes ago
Description :Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...