Search

Search Results (398836 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-101065 1 Obot-platform 1 Obot 2026-09-28 9.8 Critical
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the ability to register and launch attacker-controlled MCP servers. Because the quickstart also mounts /var/run/docker.sock into the container, the MCP runtime backend reachable this way has access to the host's Docker control surface. The fix is documentation-only: the quickstart now enables authentication, and operators who followed the previous instructions should set OBOT_SERVER_ENABLE_AUTHENTICATION=true before exposing the host to any untrusted network.
CVE-2026-101084 1 Obot-platform 1 Obot 2026-09-28 9.6 Critical
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
CVE-2026-96281 2 Flatpak, Redhat 2 Flatpak, Enterprise Linux 2026-09-28 6.2 Medium
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
CVE-2026-96283 2 Flatpak, Redhat 2 Flatpak, Enterprise Linux 2026-09-28 3.3 Low
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
CVE-2026-96282 2 Flatpak, Redhat 2 Flatpak, Enterprise Linux 2026-09-28 3.1 Low
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
CVE-2026-96284 2 Flatpak, Redhat 2 Flatpak, Enterprise Linux 2026-09-28 2.5 Low
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
CVE-2026-100903 2 , Ооо Нпо Ритм 2 Georitm, Georitm 2026-09-28 5.3 Medium
A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."
CVE-2026-87723 1 Google 1 Fuse-archive 2026-09-28 N/A
In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.
CVE-2026-82384 1 Apache 1 Roller 2026-09-28 9.8 Critical
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before authentication. The servlet is mapped unconditionally, so parsing occurs even when the global XML-RPC feature is set to disabled; no non-default configuration is required for this path. This can lead to remote code execution. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which disables the extension types and rejects requests when the XML-RPC feature is disabled.
CVE-2026-86530 1 Buffalo 2 Wex-g300, Wsr-300hp 2026-09-28 7.2 High
BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.
CVE-2026-95104 1 Buffalo 2 Wex-g300, Wsr-300hp 2026-09-28 7.5 High
Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.
CVE-2026-86507 1 Apache 1 Roller 2026-09-28 6.1 Medium
Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit comments on at least one weblog and whose moderator subsequently reviews the submitted comment; no non-default server setting is required. Users are recommended to upgrade to Apache Roller 6.1.6 or later.
CVE-2026-101018 2 Dayrui, Xunruicms 2 Xunruicms, Xunruicms 2026-09-28 4.7 Medium
A vulnerability was determined in dayrui XunruiCMS up to 4.7.2. This issue affects the function group_all_edit of the file dayrui/App/Member/Controllers/Admin/Home.php of the component Group Editing. This manipulation of the argument groupid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-82323 1 Enocta Educational Technologies Inc. 1 Enocta Platform 2026-09-28 8.1 High
Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28.
CVE-2026-59563 1 Zscaler 1 Zscaler-mcp-server 2026-09-28 4.6 Medium
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
CVE-2026-69468 1 Microsoft 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more 2026-09-28 7 High
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69470 1 Microsoft 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more 2026-09-28 7 High
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVE-2026-96273 1 Nsa 1 Ghidra 2026-09-28 5.5 Medium
Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database file that, when imported, causes the application to stall and prevents resource cleanup or graceful shutdown.
CVE-2026-94609 1 Goauthentik 1 Authentik 2026-09-28 8.8 High
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
CVE-2026-79762 1 Termix 1 Termix 2026-09-28 5.5 Medium
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap OIDC and WebAuthn users' Data Encryption Keys from committed default strings and the public userId salt in src/backend/utils/user-crypto.ts. Because OIDC_SYSTEM_SECRET and WEBAUTHN_SYSTEM_SECRET are not configured by the project's default deployment artifacts, an attacker with an offline SQLite database copy can derive the wrapping key, recover each affected user's DEK, and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected by this specific key derivation path. This issue is fixed in version 2.5.1.