π¨ CVE-2026-82472
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
π@cveNotify
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
π@cveNotify
GitHub
GitHub - documenso/documenso: The Open Source DocuSign Alternative.
The Open Source DocuSign Alternative. Contribute to documenso/documenso development by creating an account on GitHub.
π¨ CVE-2026-82870
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.
π@cveNotify
ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.
π@cveNotify
GitHub
ToolJet Database write/destroy routes trust a client-supplied organizationId with no ownership check, allowing any builder-roleβ¦
### Summary
Every write/destroy route under `server/src/modules/tooljet-db/controller.ts` -- create/rename/drop table, add/drop/edit column, add/update/delete foreign key, and bulk CSV upload -- t...
Every write/destroy route under `server/src/modules/tooljet-db/controller.ts` -- create/rename/drop table, add/drop/edit column, add/update/delete foreign key, and bulk CSV upload -- t...
π¨ CVE-2026-82871
ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.
π@cveNotify
ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. Attackers can supply arbitrary organization IDs in URL parameters to list tables, retrieve column definitions, and execute join queries to read actual stored data from victim organizations.
π@cveNotify
GitHub
ToolJet Database read routes have no per-organization authorization at all, allowing any authenticated user (any role) to readβ¦
### Summary
Three read routes under `server/src/modules/tooljet-db/controller.ts` take the target `organizationId` as a raw URL path parameter (`/organizations/:organizationId/...`): `GET .../tabl...
Three read routes under `server/src/modules/tooljet-db/controller.ts` take the target `organizationId` as a raw URL path parameter (`/organizations/:organizationId/...`): `GET .../tabl...
π¨ CVE-2026-82872
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
π@cveNotify
ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another workspace by replacing the organizationId parameter in table-management API requests.
π@cveNotify
GitHub
Workspace admin can manage ToolJet DB tables in another workspace by replacing path organizationId
In ToolJet CE `v3.20.188-lts` and `v3.20.189-lts`, a Workspace A admin can create, view, and delete
ToolJet DB tables in Workspace B by replacing the path `organizationId` on
ToolJet DB table-man...
ToolJet DB tables in Workspace B by replacing the path `organizationId` on
ToolJet DB table-man...
π¨ CVE-2026-82874
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
π@cveNotify
ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenant boundaries. Attackers can extract victim organization IDs from public app endpoints, then exploit schema operation endpoints to disclose table schemas, plant malicious tables, corrupt existing schemas, or permanently destroy victim data without any relationship to the target organization.
π@cveNotify
GitHub
Cross-tenant authorization bypass in tooljet-db schema operations allows arbitrary read/write/destruction across organization boundaries
# Cross-tenant authorization bypass in tooljet-db schema operations allows arbitrary read/write/destruction across organization boundaries
## Summary
The `tooljet-db` controller in ToolJet v3...
## Summary
The `tooljet-db` controller in ToolJet v3...
π¨ CVE-2026-82875
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.
π@cveNotify
ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's workspace. Authenticated users can enumerate, create, rename, and delete TooljetDB tables in any other workspace by manipulating the organizationId parameter in requests.
π@cveNotify
GitHub
Cross-Tenant TooljetDB Authorization Bypass
### Summary
Authenticated users in one workspace can enumerate, create, rename, and delete TooljetDB tables in any other workspace on the same instance. The TooljetDB controller accepts `organiz...
Authenticated users in one workspace can enumerate, create, rename, and delete TooljetDB tables in any other workspace on the same instance. The TooljetDB controller accepts `organiz...
π¨ CVE-2026-20274
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
π@cveNotify
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internallyβ¦
π¨ CVE-2026-20276
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.
π@cveNotify
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internallyβ¦
π¨ CVE-2026-20280
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
π@cveNotify
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internallyβ¦
π¨ CVE-2026-85176
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
π@cveNotify
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
π@cveNotify
GitHub
GitHub - dbgate/dbgate: Database manager for MySQL, PostgreSQL, SQL Server, MongoDB, SQLite and others. Runs under Windows, Linuxβ¦
Database manager for MySQL, PostgreSQL, SQL Server, MongoDB, SQLite and others. Runs under Windows, Linux, Mac or as web application - dbgate/dbgate
π¨ CVE-2026-68845
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-68847
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-68848
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69314
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-69316
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
π@cveNotify
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-69333
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69344
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
π@cveNotify
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-69348
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69351
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-43697
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
π@cveNotify
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
π@cveNotify
Apple Support
About the security content of macOS Golden Gate 27 - Apple Support
This document describes the security content of macOS Golden Gate 27.
π¨ CVE-2026-43785
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read.
π@cveNotify
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read.
π@cveNotify
Apple Support
About the security content of iOS 27 and iPadOS 27 - Apple Support
This document describes the security content of iOS 27 and iPadOS 27.