CVE Notify
19.7K subscribers
4 photos
264K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-67286
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-15803
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the earlier fix did not cover all parser entry points. The issue is resolved in RDF4J 5.3.2, which rejects or disables DOCTYPE declarations, external entities, and external DTD loading by default.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-65926
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-68758
A low-privileged authenticated user may access restricted support information under specific conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-68759
A holder of a valid integration credential may impersonate other users under specific conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-69107
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-48550
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary JavaScript in the victim's browser.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73237
XSS vulnerability in Markdown handling in Apache Allura.

This issue affects Apache Allura: from 1.10.0 before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73238
XSS vulnerability in code display in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73239
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73240
Specifically crafted inputs may lead to git argument injection in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-16627
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18673
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication.



An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18675
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.



The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token



A single request is a transient interruption; sustaining an outage requires repeated requests.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18676
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18677
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18678
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.



An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.

๐ŸŽ–@cveNotify