CVE tracker
393 subscribers
5.78K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-105126 - LaraDashboard before 1.4.8 Privilege Escalation via Superadmin Role Tampering

CVE ID :CVE-2026-105126
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105127 - LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints

CVE ID :CVE-2026-105127
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105128 - LaraDashboard before 1.4.8 Open Redirect via Email Template Builder redirect_url

CVE ID :CVE-2026-105128
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105129 - LaraDashboard before 1.4.8 Incorrect Authorization Exposes Secrets via Settings API

CVE ID :CVE-2026-105129
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail credentials, passwords and tokens.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105130 - LaraDashboard 1.4.0 before 1.4.8 Race Condition Bypasses Per-IP Registration Limit

CVE ID :CVE-2026-105130
Published : Oct. 4, 2026, 12:16 a.m. | 3 hours, 43 minutes ago
Description :LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass RegistrationGuardService::hasExceededIpLimit before recordRegistration runs, creating accounts in bulk and defeating anti-automation controls.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105096 - Omega Solution CoinEx Crypto Customer Profile API customer authorization

CVE ID :CVE-2026-105096
Published : Oct. 4, 2026, 2:16 a.m. | 1 hour, 43 minutes ago
Description :A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105131 - mayswind ezBookkeeping 1.2.0 before 2.0.1 Privilege Escalation via Token Refresh Endpoint

CVE ID :CVE-2026-105131
Published : Oct. 4, 2026, 2:16 a.m. | 1 hour, 43 minutes ago
Description :ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers can exchange short-lived or IP-restricted API tokens for 30-day normal session tokens that bypass API token expiry and allowlists.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88779 - Memory overflow vulnerability leading to Denial of Service

CVE ID :CVE-2026-88779
Published : Oct. 4, 2026, 2:35 a.m. | 1 hour, 24 minutes ago
Description :Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105098 - Omega Solution CoinEx Crypto Support Ticket API customer information disclosure

CVE ID :CVE-2026-105098
Published : Oct. 4, 2026, 2:45 a.m. | 1 hour, 14 minutes ago
Description :A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support Ticket API. The manipulation of the argument status/page/count results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105097 - Omega Solution CoinEx Crypto Customer Information API customer-currency authorization

CVE ID :CVE-2026-105097
Published : Oct. 4, 2026, 3:16 a.m. | 43 minutes ago
Description :A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105157 - RainyGao DocSys Document Controller doGetTmpFile.do DocController.doGetTmp path traversal

CVE ID :CVE-2026-105157
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105158 - RainyGao DocSys Database Management BaseController.java BaseController.createDBForMysql sql injection

CVE ID :CVE-2026-105158
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105205 - SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo

CVE ID :CVE-2026-105205
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document. Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105206 - ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service

CVE ID :CVE-2026-105206
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105207 - ZITADEL before 4.17.3 Account Takeover via External IdP Linking

CVE ID :CVE-2026-105207
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105208 - ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens

CVE ID :CVE-2026-105208
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105209 - ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment

CVE ID :CVE-2026-105209
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105210 - ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers

CVE ID :CVE-2026-105210
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105211 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode

CVE ID :CVE-2026-105211
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105212 - ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment

CVE ID :CVE-2026-105212
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105213 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations

CVE ID :CVE-2026-105213
Published : Oct. 4, 2026, 3:16 p.m. | 7 hours, 22 minutes ago
Description :ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...