🚨 CVE-2026-20696
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.
🎖@cveNotify
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.4. An app may be able to access sensitive user data.
🎖@cveNotify
Apple Support
About the security content of macOS Sequoia 15.7.4 - Apple Support
This document describes the security content of macOS Sequoia 15.7.4.
🚨 CVE-2026-77995
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
🎖@cveNotify
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins.
🎖@cveNotify
Miniorange
miniOrange Security Software: IAM, PAM, IGA, MDM, DLP, Data Privacy & AI Security
miniOrange offers wide range of security products including IAM, PAM, IGA, MDM, DLP, Data Privacy & AI Security
🚨 CVE-2026-78367
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
🎖@cveNotify
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb).
🎖@cveNotify
Redhat
CVE-2026-78367 - Red Hat Customer Portal
CVE Details App
🚨 CVE-2026-18957
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19043
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19051
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-19080
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting.
This issue affects Menulux Portal: before 20260903211448.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-85577
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.
🎖@cveNotify
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's browser context on the login page.
🎖@cveNotify
GitHub
Reflected XSS: userLogin.php echoes addslashes($_GET['error']) inside a script block, and addslashes does not escape </script>…
## Summary
`view/userLogin.php:276` echoes `addslashes($_GET['error'])` inside a `<script>` block. `addslashes()` escapes `'`, `"`, `\`, and NUL but does not escape `</sc...
`view/userLogin.php:276` echoes `addslashes($_GET['error'])` inside a `<script>` block. `addslashes()` escapes `'`, `"`, `\`, and NUL but does not escape `</sc...
🚨 CVE-2026-85578
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
🎖@cveNotify
SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers with reader role can access private workspace files including notebook metadata and internal configuration by knowing the hidden notebook identifier and file path.
🎖@cveNotify
GitHub
Reader can read files from an explicitly hidden notebook
### Summary
A reader-role authorization bypass in `/api/file/getFile` allows retrieval of normal files below a notebook explicitly configured as `Visible:false` in publish access. The same raw-fil...
A reader-role authorization bypass in `/api/file/getFile` allows retrieval of normal files below a notebook explicitly configured as `Visible:false` in publish access. The same raw-fil...
🚨 CVE-2026-85579
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
🎖@cveNotify
SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed.
🎖@cveNotify
GitHub
Reader-role undoState discloses private related document root IDs
### Summary
The reader-accessible `POST /api/transactions/undoState` endpoint returns the `peekMutatedRootIDs` list from the global undo-log stack for a caller-supplied root ID. The list is copi...
The reader-accessible `POST /api/transactions/undoState` endpoint returns the `peekMutatedRootIDs` list from the global undo-log stack for a caller-supplied root ID. The list is copi...
🚨 CVE-2026-85580
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
🎖@cveNotify
GitHub
Linux MCP publish-access path guard bypass exposes publishAccess.json
### Summary
On Linux, the MCP file-access path guard compares a case-variant path against the protected `publishAccess.json` filename using case-sensitive matching. A read-only MCP request can u...
On Linux, the MCP file-access path guard compares a case-variant path against the protected `publishAccess.json` filename using case-sensitive matching. A read-only MCP request can u...
🚨 CVE-2026-85581
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.
🎖@cveNotify
SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.
🎖@cveNotify
GitHub
Unauthenticated UI-process registration retains attacker-controlled identifiers without bound
### Summary
The public `/api/system/uiproc` endpoint accepts attacker-controlled UI-process identifiers and retains them in a global registry without a size limit or authentication requirement. ...
The public `/api/system/uiproc` endpoint accepts attacker-controlled UI-process identifiers and retains them in a global registry without a size limit or authentication requirement. ...
🚨 CVE-2026-85582
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growth and denial of service.
🎖@cveNotify
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growth and denial of service.
🎖@cveNotify
GitHub
Publish-service Basic Auth creates unbounded persistent sessions
### Summary
Successful publish-service Basic Auth requests create persistent session entries keyed by newly issued session cookies. The registry has no effective TTL or size bound for valid sess...
Successful publish-service Basic Auth requests create persistent session entries keyed by newly issued session cookies. The registry has no effective TTL or size bound for valid sess...
🚨 CVE-2026-85583
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.
🎖@cveNotify
GitHub
Reader-role file API follows workspace assets symlinks outside the workspace
### Summary
The reader-accessible file-read endpoint performs lexical workspace and publish checks but follows a symlink when opening an authorized asset path. A reader can request a logical ass...
The reader-accessible file-read endpoint performs lexical workspace and publish checks but follows a symlink when opening an authorized asset path. A reader can request a logical ass...
🚨 CVE-2026-85584
SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies. Unauthenticated attackers can submit repeated authentication requests with unique invalid usernames to exhaust memory and increase synchronization overhead, degrading service availability.
🎖@cveNotify
SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle that stores failed-attempt state using attacker-controlled usernames without enforcing capacity limits or eviction policies. Unauthenticated attackers can submit repeated authentication requests with unique invalid usernames to exhaust memory and increase synchronization overhead, degrading service availability.
🎖@cveNotify
GitHub
Publish-auth throttling retains unique invalid-user keys without a bound
### Summary
The publish-service Basic Auth throttle stores failed-attempt state under a key derived from the remote address and username. Every unique invalid username creates a persistent map e...
The publish-service Basic Auth throttle stores failed-attempt state under a key derived from the remote address and username. Every unique invalid username creates a persistent map e...
🚨 CVE-2026-85585
SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization overhead, degrading availability.
🎖@cveNotify
SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization overhead, degrading availability.
🎖@cveNotify
GitHub
Unauthenticated unique request paths grow the global ControlConcurrency map without bound
## Summary
SiYuan’s request-concurrency middleware retains a mutex entry for every non-exempt request path. The path-keyed global map has no eviction or size bound, so an unauthenticated calle...
SiYuan’s request-concurrency middleware retains a mutex entry for every non-exempt request path. The path-keyed global map has no eviction or size bound, so an unauthenticated calle...
🚨 CVE-2026-85586
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
🎖@cveNotify
phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.
🎖@cveNotify
GitHub
CAPTCHA bypass on anonymous question submission via store=now parameter
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...
🚨 CVE-2026-85587
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
🎖@cveNotify
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
🎖@cveNotify
GitHub
Incorrect permission checks on admin content pages disclose draft/inactive content (news edit, FAQ translate)
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...
🚨 CVE-2026-85588
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
🎖@cveNotify
phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attackers obtaining exported archives can extract the TOTP seed and generate valid one-time codes to bypass two-factor authentication.
🎖@cveNotify
GitHub
Live TOTP secret included in user data export ZIP
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...
🚨 CVE-2026-85589
phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters regardless of their privilege level.
🎖@cveNotify
phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters regardless of their privilege level.
🎖@cveNotify
GitHub
Missing authorization on admin dashboard API endpoints (searches, content-health) — any authenticated user
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...
🚨 CVE-2026-85591
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only a CSRF token to silently change any user's password, including administrators, causing irreversible account takeover and victim lockout.
🎖@cveNotify
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control panel API endpoint that allows authenticated attackers to change account passwords without verifying the current password. Attackers with session access can submit a PUT request to the user data update endpoint with only a CSRF token to silently change any user's password, including administrators, causing irreversible account takeover and victim lockout.
🎖@cveNotify
GitHub
Unverified password change in user control panel API (no current-password verification)
> **Authorized research notice:** This vulnerability was discovered during authorized security research in an isolated lab environment against a local instance of phpMyFAQ (main @ 9435f34bd8fcaa...