π¨ CVE-2026-56730
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to access. The vulnerable GraphQL mutation is meant to transform a knowledge base answer suggestion so it can be inserted into the ticket editor, but it only checks if the user has the ticket.agent permission. Checking the authorization to the knowledge base answer itself is missing. This vulnerability is fixed in 7.0.2.
π@cveNotify
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerability was found that allows an authenticated agent to read knowledge base answer content they should not be able to access. The vulnerable GraphQL mutation is meant to transform a knowledge base answer suggestion so it can be inserted into the ticket editor, but it only checks if the user has the ticket.agent permission. Checking the authorization to the knowledge base answer itself is missing. This vulnerability is fixed in 7.0.2.
π@cveNotify
GitHub
Maintenance: Improve knowledge base answer suggestion transforming. Β· zammad/zammad@b059bd1
(cherry picked from commit f2b16d683c8ada4d831a68b50d091a02fee37245)
ee268f1a Maintenance: Improve knowlege base answer suggestion transforming.
Co-authored-by: Florian Liebe <fl@zammad.com>
ee268f1a Maintenance: Improve knowlege base answer suggestion transforming.
Co-authored-by: Florian Liebe <fl@zammad.com>
π¨ CVE-2026-56734
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target address. An actor who controls their profile at a connected provider may cause the server to connect to internal network locations. Response timing and error patterns differ between reachable and unreachable targets, allowing internal service probing. Worker processes may be blocked for several seconds per request. Requires a configured external authentication provider where the actor can modify their profile image URL. This issue is fixed in version 7.0.2.
π@cveNotify
Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAuth/OIDC/SAML), a profile image URL from the external identity provider is fetched without verifying the target address. An actor who controls their profile at a connected provider may cause the server to connect to internal network locations. Response timing and error patterns differ between reachable and unreachable targets, allowing internal service probing. Worker processes may be blocked for several seconds per request. Requires a configured external authentication provider where the actor can modify their profile image URL. This issue is fixed in version 7.0.2.
π@cveNotify
GitHub
Maintenance: Improve fetching of avatars. Β· zammad/zammad@1fae97d
Zammad is a web based open source helpdesk/customer support system. - Maintenance: Improve fetching of avatars. Β· zammad/zammad@1fae97d
π¨ CVE-2026-97882
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file loginlinkfaculty.php of the component Faculty Authentication. Executing a manipulation of the argument fid/pass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
GitHub - smithbraz/PoC-CloudClassroom-AuthBypass: Proof of Concept - Authentication Bypass on Faculty Login Panel - CloudClassroomβ¦
Proof of Concept - Authentication Bypass on Faculty Login Panel - CloudClassroom PHP Project 1.0 - smithbraz/PoC-CloudClassroom-AuthBypass
π¨ CVE-2026-100192
X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.
π@cveNotify
X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and impersonation attacks.
π@cveNotify
GitHub
cve-request-poc/x-springboot/01_app-credential-sms-abuse.py at master Β· LinYuanyi1/cve-request-poc
poc repo. Contribute to LinYuanyi1/cve-request-poc development by creating an account on GitHub.
π¨ CVE-2026-63205
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.
π@cveNotify
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img tag pointing to any existing attachment, the system copies that attachment into a new signature-owned record, without checking whether the user has permission to access the original attachment. The newly created copy is then downloadable by the same channel-admin user, because attachment access is determined by the copy's owner (the signature), not the original object (e.g., a ticket or knowledge-base article). This allows a user with any of the admin.channel_email, admin.channel_google, admin.channel_microsoft365, or admin.channel_microsoft_graph permissions to read attachments they would otherwise be denied access to, such as ticket attachments belonging to groups they are not a member of. This issue is fixed in version 7.1.2.
π@cveNotify
GitHub
Maintenance: Improve referenced attachments handling Β· zammad/zammad@f3e4da8
Zammad is a web based open source helpdesk/customer support system. - Maintenance: Improve referenced attachments handling Β· zammad/zammad@f3e4da8
π¨ CVE-2026-84463
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer is rendered, that value is inserted into the page's HTML without being escaped for its attribute context, allowing it to break out and inject additional HTML into the page. When another user who has permission to switch between user sessions views the affected answer, the injected HTML causes their browser to silently send a request to Zammad's session-switching endpoint using their own active credentials. This results in switching their session to an account chosen by the person who wrote the Knowledge Base answer. No action is required from the viewer beyond opening the published answer. This issue is fixed in version 7.1.2.
π@cveNotify
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer is rendered, that value is inserted into the page's HTML without being escaped for its attribute context, allowing it to break out and inject additional HTML into the page. When another user who has permission to switch between user sessions views the affected answer, the injected HTML causes their browser to silently send a request to Zammad's session-switching endpoint using their own active credentials. This results in switching their session to an account chosen by the person who wrote the Knowledge Base answer. No action is required from the viewer beyond opening the published answer. This issue is fixed in version 7.1.2.
π@cveNotify
GitHub
Maintenance: Improve handling of knowledge base video markers. Β· zammad/zammad@f7a97ea
Approved-by: Mantas Masalskis <mm@zammad.com>
π¨ CVE-2026-94397
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-183)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.0.0β¦
π¨ CVE-2026-94398
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-179)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.12.0β¦
π¨ CVE-2026-94399
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-180)
Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: All versions from 8.0.0β¦
π¨ CVE-2026-94400
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
π@cveNotify
Discuss the Elastic Stack
Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-181)
Uncontrolled Resource Consumption in Kibana Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: Fixes should be back-ported to all maintainedβ¦
π¨ CVE-2026-101141
A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
π¨ CVE-2026-101914
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
π@cveNotify
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison when case-insensitive matching is enabled. If one service method name prefixes another and the methods have different access rules, a request for the longer method can match the shorter method's rule and cause incorrect authorization. This issue is fixed in versions 1.13.1 and 1.14.1.
π@cveNotify
GitHub
grpc-js-xds: Fix case-insensitive exact path matcher behavior Β· grpc/grpc-node@6cf64b5
gRPC for Node.js. Contribute to grpc/grpc-node development by creating an account on GitHub.
π¨ CVE-2026-87741
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed on the callback, and sanitize_text_field() β applied to the $style value before it is concatenated directly into a shortcode string evaluated by do_shortcode() β does not strip shortcode delimiters, allowing an attacker to inject a second, fully attacker-controlled [smile_modal] invocation that causes smile_modal_popup() to pass attacker-supplied base64-decoded bytes to maybe_unserialize() with no allowed_classes restriction. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
π@cveNotify
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed on the callback, and sanitize_text_field() β applied to the $style value before it is concatenated directly into a shortcode string evaluated by do_shortcode() β does not strip shortcode delimiters, allowing an attacker to inject a second, fully attacker-controlled [smile_modal] invocation that causes smile_modal_popup() to pass attacker-supplied base64-decoded bytes to maybe_unserialize() with no allowed_classes restriction. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
π@cveNotify
Convert Pro
Convert Pro - The Best Lead Generation Tool for WordPress
Convert Pro is a powerful lead generation tool that converts your website traffic into leads. Get 300 more leads with Convert Pro.
π¨ CVE-2026-100392
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.
π@cveNotify
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest / read-only), destroying the root account's privilege and locking the legitimate owner out of the instance. At time of publication, there are no publicly available patches.
π@cveNotify
GitHub
Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization)
## Summary & Historical Context
Recent hardening efforts have progressively tightened the user-management boundary around the Primary Administrator (`user_id = 1`).
**PR #1638** closed the...
Recent hardening efforts have progressively tightened the user-management boundary around the Primary Administrator (`user_id = 1`).
**PR #1638** closed the...
π¨ CVE-2026-101144
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
π¨ CVE-2026-101187
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device Management API. This manipulation of the argument path causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
ZHOME_A0101/pop_usb_device_path_command_injection.md at main Β· Wlz1112/ZHOME_A0101
Contribute to Wlz1112/ZHOME_A0101 development by creating an account on GitHub.
π¨ CVE-2026-102266
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an attacker signs an HMAC token with the same zero-length key accepted by PyJWT. Consequently, forged token can carry arbitrary authenticated claims. This issue is fixed in version 2.14.0.
π@cveNotify
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an attacker signs an HMAC token with the same zero-length key accepted by PyJWT. Consequently, forged token can carry arbitrary authenticated claims. This issue is fixed in version 2.14.0.
π@cveNotify
GitHub
Validate PyJWK HMAC keys consistently Β· jpadilla/pyjwt@f91ed44
JSON Web Token implementation in Python. Contribute to jpadilla/pyjwt development by creating an account on GitHub.
π¨ CVE-2026-102270
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, is_pem_format performs unbounded backtracking while searching for a PEM end marker. Consequently, an attacker can cause intensive CPU consumption. This issue is fixed in version 2.14.0.
π@cveNotify
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, is_pem_format performs unbounded backtracking while searching for a PEM end marker. Consequently, an attacker can cause intensive CPU consumption. This issue is fixed in version 2.14.0.
π@cveNotify
GitHub
fix: reject loader-accepted PEM variants Β· jpadilla/pyjwt@8b4e233
JSON Web Token implementation in Python. Contribute to jpadilla/pyjwt development by creating an account on GitHub.
π¨ CVE-2026-102274
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result, one malformed member aborts construction of the entire PyJWKSet. Consequently, applications can experience authentication failures or request-level denial of service. This issue is fixed in version 2.14.0.
π@cveNotify
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result, one malformed member aborts construction of the entire PyJWKSet. Consequently, applications can experience authentication failures or request-level denial of service. This issue is fixed in version 2.14.0.
π@cveNotify
GitHub
Skip malformed JWKs in JWK sets Β· jpadilla/pyjwt@8915570
JSON Web Token implementation in Python. Contribute to jpadilla/pyjwt development by creating an account on GitHub.
π¨ CVE-2026-102277
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
π@cveNotify
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12.
π@cveNotify
GitHub
Merge commit from fork Β· juliangruber/brace-expansion@33a5ef1
Bash keeps a quirk where a brace group followed by a comma set still expands
(`{a},b}`). The parser implements it by rewriting the string and restarting
the scan, absorbing one `}` per pass, so `n`...
(`{a},b}`). The parser implements it by rewriting the string and restarting
the scan, absorbing one `}` per pass, so `n`...
π¨ CVE-2026-97027
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.
π@cveNotify
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.
π@cveNotify
Redhat
CVE-2026-97027 - Red Hat Customer Portal
CVE Details App