Overzicht van binnengekomen advisories.
1553 resultaten gevonden
A security vulnerability in the @hulumi/policies npm package affects versions before 1.3.2. The package fails to fully inspect inline and attached IAM policy documents when evaluating the administrator-policy guardrail. This allows attackers to craft admin-equivalent policy paths that bypass policy evaluation controls. The flaw effectively grants unauthorized administrative access to those who exploit it. The vulnerability has been assigned CVE-2026-82860 and is rated high severity. Users are advised to upgrade to version 1.3.2 or later to remediate the issue. The advisory has been published on both the GitHub Security Advisories page and VulnCheck.
Bekijk origineel advisory →CVE-2026-82872 affects ToolJet versions before v3.16.208, where the application fails to validate that the organizationId in API request paths matches the authenticated user's workspace. This flaw allows a workspace admin to perform unauthorized database table operations—including creating, viewing, and deleting tables—in other workspaces by manipulating the organizationId parameter in table-management API requests. The vulnerability is classified as an authorization bypass or Insecure Direct Object Reference (IDOR) issue. It poses a significant risk to multi-tenant ToolJet deployments where data isolation between workspaces is critical. The fix is included in ToolJet v3.16.208 and later. Organizations using older versions should upgrade immediately to prevent cross-workspace data exposure or manipulation.
Bekijk origineel advisory →A critical Unrestricted Upload of File with Dangerous Type vulnerability has been identified in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages. The vulnerability affects all versions up to and including 4.4.1. Exploitation of this flaw allows attackers to upload malicious files to the affected WordPress installation. This type of vulnerability can lead to remote code execution, full site compromise, or deployment of web shells. The issue is tracked as CVE-2026-82970 and has been published by both NVD/NIST and Patchstack. WordPress site administrators using this plugin are advised to update to a patched version immediately. No workaround details are provided beyond patching.
Bekijk origineel advisory →A critical incorrect access control vulnerability exists in the delWiFiAclRules function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to delete Wi-Fi ACL (Access Control List) rules by sending a specially crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication or credentials are required to exploit this vulnerability. Successful exploitation could allow attackers to bypass network access controls enforced via Wi-Fi ACL rules, potentially enabling unauthorized devices to connect to protected networks. The vulnerability has been documented and coordinated through GitHub repositories linked to CVE vendor coordination efforts. TOTOLINK has been notified and firmware download references are available on their official website.
Bekijk origineel advisory →Wallos, an open-source self-hostable subscription tracker, contains a critical authentication vulnerability in versions 4.0.0 through 4.9.5. The OIDC login flow matches incoming identities to local accounts solely based on the email claim, without checking the email_verified flag from the Identity Provider. An attacker can exploit this by authenticating via an IdP that allows arbitrary or unverified email addresses, such as multi-tenant or open self-registration IdPs. By presenting an admin's email address during OIDC login, an attacker with no existing Wallos account can gain full administrative access without knowing any password. This constitutes a complete account takeover vulnerability. The flaw is especially dangerous when Wallos is configured against permissive or attacker-controlled IdPs. The vulnerability has been patched in version 4.9.6, and users are strongly advised to upgrade immediately.
Bekijk origineel advisory →A critical vulnerability in elFinder (open-source web file manager) prior to version 2.1.70 allows remote code execution via a MIME type normalization bypass. The checkExtractItems() function fails to pass results through mimeTypeNormalize(), causing PHP-executable extensions (.phtml, .phar, .php5, .php3) to bypass upload denial rules. Attackers with ZIP upload permissions can extract PHP files into web-accessible directories and execute arbitrary code. The root cause is that these extensions are absent from mime.types, so staticMimeMap entries mapping them to text/x-php are never applied. The allowPutMime() function then incorrectly permits extraction even when uploadDeny blocks text/x-php. The vulnerability is fixed in elFinder version 2.1.70 with two separate commits addressing the issue.
Bekijk origineel advisory →CVE-2026-77966 affects an Ebyte product that fails to properly separate limited user and administrative management functions. A low-privileged authenticated attacker can access security-sensitive configuration functions without proper authorization. The vulnerability allows modification of device settings that impact confidentiality, integrity, or availability. This is classified as an improper access control / privilege escalation issue in an OT/IoT device. The vulnerability was reported via NVD and has an associated CISA ICS advisory (ICSA-26-237-06). The issue poses a significant risk in operational technology environments where device integrity is critical. No exploit code is publicly referenced, but the low privilege requirement lowers the bar for exploitation.
Bekijk origineel advisory →A vulnerability has been identified in Soarkey StudentManagement (学生信息管理系统) affecting versions up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. The flaw resides in the AdminDao.doGet function within the file code/src/service/AdminDao.java, part of the Administrative Servlet component. By manipulating the 'action' argument, an attacker can achieve authorization bypass remotely. A public exploit is already available, increasing the risk of active exploitation. The project maintainer was notified via a GitHub issue report but has not responded. This is a remotely exploitable, publicly disclosed vulnerability with no known patch or vendor acknowledgment at the time of reporting.
Bekijk origineel advisory →CVE-2026-82858 affects @hulumi/drift versions before 1.3.2, where the library accepts externally supplied execute plans without sufficient provenance validation. This flaw allows untrusted reconciliation input to be treated as trusted, enabling attackers to supply malicious execute plans. By doing so, attackers can bypass security checks and perform unsafe reconciliation operations. The vulnerability is classified as high severity. Users are advised to upgrade to version 1.3.2 or later to mitigate the risk. The issue was disclosed via GitHub Security Advisories and VulnCheck.
Bekijk origineel advisory →A local privilege escalation vulnerability has been identified in ieungSoft Ultra RAMDisk Pro version 1.82. The vulnerability resides in the URDSCSI.sys kernel driver and involves improper privilege management. An attacker with local access can exploit this flaw to escalate privileges on the affected system. The exploit has been publicly disclosed and is available for use, increasing the risk of exploitation. The vulnerability was responsibly disclosed to the vendor, but no response was received. The attack vector is local, limiting remote exploitation but still posing significant risk in shared or multi-user environments. The issue is tracked as CVE-2026-82807 and has been documented across multiple security databases.
Bekijk origineel advisory →CVE-2026-51681 describes an incorrect access control vulnerability in the setRemoteCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to expose WAN-side administration interfaces by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, significantly lowering the attack barrier. Successful exploitation could allow attackers to gain administrative access to the router from the WAN side, potentially enabling full device compromise. The vulnerability was disclosed via NVD and coordinated through GitHub repositories by researchers DarkBoulder and ShengWu00. TOTOLINK has been notified as part of vendor coordination efforts. The affected product is a consumer/SOHO router, making it a risk for both home and small business environments. Mitigation likely involves a firmware update from TOTOLINK.
Bekijk origineel advisory →A SQL injection vulnerability (CVE-2026-82614) has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw resides in the loadResultList function within the Product Category Filter Interface, accessible via /index.php?q=product. Attackers can manipulate the 'Category' argument to inject malicious SQL queries. The attack can be launched remotely without requiring physical access. A working exploit has been publicly published, increasing the risk of active exploitation. The vulnerability poses a significant risk to any organization running this software as it could lead to unauthorized database access or data exfiltration. No patch information is currently noted in the article.
Bekijk origineel advisory →Wallos, an open-source self-hostable personal subscription tracker, contains a critical authentication bypass vulnerability prior to version 4.9.4. The endpoint endpoints/db/migrate.php can be accessed over HTTP without any authentication, allowing any unauthenticated attacker to trigger database schema migrations against the live SQLite database. This could lead to database corruption, data loss, or unauthorized schema changes. The vulnerability requires no credentials or special privileges to exploit, making it easily accessible to remote attackers. The issue has been remediated in version 4.9.4, which was released along with a security advisory. Users are strongly advised to upgrade to the patched version immediately to prevent potential exploitation.
Bekijk origineel advisory →A critical Missing Authentication for Critical Function vulnerability (CVE-2026-58574) has been identified in Dell PowerStore storage appliances. An unauthenticated attacker with network access to the restricted management interface can exploit this flaw to read internal system information from the appliance filesystem. The vulnerability is rated Critical due to its potential to expose sensitive information and credentials, ultimately enabling full administrative access to the storage array. No authentication is required to exploit this vulnerability, making it particularly dangerous in environments where the management interface is accessible over a network. Dell has released a security advisory (DSA-2026-330) addressing this and multiple other vulnerabilities in Dell PowerStore T.
Bekijk origineel advisory →A critical vulnerability exists in the Phison PS3111-S11 storage controller firmware where RSA signature verification is fundamentally broken. The firmware validates signatures using a public modulus embedded within the firmware image itself rather than storing it in immutable, trusted hardware storage. This design flaw allows attackers to generate their own RSA key pairs, sign malicious firmware with the private key, and embed the corresponding public modulus into the firmware image. The controller then accepts this attacker-crafted firmware as legitimate, completely bypassing firmware integrity protections. This vulnerability enables persistent, low-level compromise of storage devices using the affected controller, potentially surviving OS reinstalls and standard security measures. The attack could be used to deploy firmware-level implants or destructive payloads on affected drives. Public proof-of-concept tooling and detailed writeups are available, significantly lowering the barrier to exploitation.
Bekijk origineel advisory →ToolJet versions before v3.16.208 contain a critical authorization flaw where the organizationId ownership is not validated in database write and destroy routes. This allows any user with a builder role to create, alter, or drop tables belonging to other organizations in shared instances. The missing organization-resolving guards enable attackers to cross tenant boundaries and permanently delete tables, insert arbitrary data, and modify schemas. This is a multi-tenant isolation failure that poses significant risks to shared ToolJet deployments. Organizations using ToolJet in a multi-tenant configuration should upgrade to v3.16.208 or later immediately to remediate the vulnerability.
Bekijk origineel advisory →A critical incorrect access control vulnerability exists in the setPasswordCfg function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to change the administrator account credentials without any prior authentication. Exploitation is achieved by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. This effectively grants full administrative control of the affected router to an attacker. The vulnerability has been documented by multiple researchers and coordinated with the vendor. TOTOLINK T6 is a consumer/SOHO network router, making this vulnerability particularly impactful for home and small business users. No authentication or special privileges are required to exploit this flaw. The issue represents a severe security risk as it enables complete device takeover.
Bekijk origineel advisory →A missing authentication vulnerability was identified in Tenda AC1206 firmware version 15.03.06.23. The flaw exists in the R7WebsSecurityHandler function within the /goform/ate endpoint of the device's Web UI component. An unauthenticated remote attacker can exploit this vulnerability without any credentials. The attack vector is network-based and requires no user interaction. A public exploit is already available, increasing the risk of active exploitation. This type of vulnerability in consumer and SOHO routers poses significant risks to network security. The affected product is a widely used wireless router from the Chinese manufacturer Tenda. The availability of a public proof-of-concept makes immediate patching or mitigation highly advisable.
Bekijk origineel advisory →ToolJet versions before v3.16.208 contain a critical authorization flaw where the organizationId ownership is not validated in database write and destroy routes. This allows any authenticated user with a builder role to create, alter, or drop tables belonging to other organizations on shared instances. The missing organization-resolving guards enable cross-tenant boundary violations, permitting attackers to permanently delete tables, insert arbitrary data, and modify database schemas. The vulnerability poses a serious risk to multi-tenant deployments of ToolJet. Organizations using shared ToolJet instances should upgrade to v3.16.208 or later immediately to remediate the issue.
Bekijk origineel advisory →CVE-2026-51725 describes an incorrect access control vulnerability in the NTPSyncWithHost function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to manipulate the device's system clock by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint. No authentication is required to exploit this vulnerability, making it trivially accessible to any attacker with network access to the device. Manipulation of the device clock can have downstream effects on time-sensitive security mechanisms such as certificate validation, logging accuracy, and scheduled tasks. The vulnerability was coordinated and disclosed via GitHub repositories associated with CVE vendor coordination efforts. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. This issue highlights ongoing access control weaknesses in consumer and SOHO router firmware from TOTOLINK.
Bekijk origineel advisory →