{"success":true,"data":{"threats":[{"id":"3bf08fc2-f979-47eb-8137-2ed226d94f56","slug":"cve-2026-104078","externalId":"CVE-2026-104078","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute …","description":"Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \\href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formula that renders as a javascript: URL anchor, which when clicked by the victim in Live Preview executes in the Node-integration-enabled vault renderer via require('child_process'), achieving arbitrary operating system command execution as the desktop user.","cveId":"CVE-2026-104078","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:11.753Z","addedAt":"2026-10-08T18:39:31.662Z","updatedAt":"2026-10-08T23:06:38.563Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104078","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104078","note":"authoritative record"}]},{"id":"3df3df2c-6318-4caa-bb24-2141a14b3b4a","slug":"cve-2026-104077","externalId":"CVE-2026-104077","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104077 — Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting in…","description":"Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because Node integration is enabled and context isolation is disabled in Obsidian's vault renderer, the injected script can call parent.require() to access Node APIs such as fs and child_process, enabling arbitrary operating system command execution when the victim opens the note and manually starts the presentation.","cveId":"CVE-2026-104077","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-79","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://obsidian.md/changelog/2026-10-05-desktop-v1.14.4/","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:11.603Z","addedAt":"2026-10-08T18:39:31.654Z","updatedAt":"2026-10-08T23:06:38.547Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104077","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104077","note":"authoritative record"}]},{"id":"2e5fd461-6d43-4c95-ba76-746227e5841c","slug":"cve-2026-76276","externalId":"CVE-2026-76276","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76276 — In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could…","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and Navigating Splunk Web (https://help.splunk.com/en/splunk-enterprise/search/search-tutorial/10.4/part-1-getting-started/navigating-splunk-web) in the Splunk documentation.\n\nSplunk Enterprise versions 9.4.x are not affected.","cveId":"CVE-2026-76276","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00176,"epssPercentile":0.06576,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:18.760Z","addedAt":"2026-10-07T22:39:36.664Z","updatedAt":"2026-10-08T21:05:44.522Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76276","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76276","note":"authoritative record"}]},{"id":"dce5e97f-9ce1-4a80-9aef-58b94f07d04a","slug":"cve-2026-33586","externalId":"CVE-2026-33586","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-33586 — Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.","description":"Authenticated users are able to manipulate both the SMTP\nenvelope “Envelope-from” and “From” fields when sending\nemails through OVH mail servers.\n\n\n\nDue to OVH's default SPF configuration, which\ncommonly includes include:mx.ovh.com, any authenticated user with a\nvalid OVH email account can send messages that appear to originate from any\nOVH-hosted domains using the default SPF record. Since the SPF policy\nexplicitly authorizes OVH mail servers (mx.ovh.com) to send mail on behalf of\nthese domains, forged messages successfully pass SPF validation despite\nnot being authorized by the impersonated domain owner.","cveId":"CVE-2026-33586","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-346","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://docs.ovhcloud.com/en/guides/web-cloud/email-and-collaborative-solutions/troubleshooting/email-rejected-cross-domain-spoofing","type":"advisory","title":"a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"}],"epssScore":0.00139,"epssPercentile":0.02813,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.643Z","addedAt":"2026-10-07T16:39:32.781Z","updatedAt":"2026-10-08T23:06:36.659Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33586","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-33586","note":"authoritative record"}]},{"id":"696af58e-47dc-4110-b752-5616f72a4f77","slug":"cve-2026-105744","externalId":"CVE-2026-105744","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105744 — Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem.","description":"Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine=\"tectonic\") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \\openin and \\openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling the tikz_engine_allow_shell_escape option additionally permits shell commands through TeX. The default configuration, which does not enable Tectonic rendering, is not affected. This vulnerability is fixed in 2.132.0.","cveId":"CVE-2026-105744","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"docling","product":"docling","affectedVersions":[">= 2.94.0, < 2.132.0","pkg:pypi/docling >= 2.94.0, < 2.132.0","pkg:pypi/docling-slim >= 2.94.0, < 2.132.0"],"cwes":["CWE-22","CWE-73","CWE-1188"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-x3q2-h9hx-4r4j","ecosystem:pypi","osv:pysec-2026-4191"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/docling-project/docling/commit/38b6fa0a465d46fdacbbec333f50fa19c4f6b342","https://github.com/docling-project/docling/pull/4419","https://github.com/docling-project/docling/security/advisories/GHSA-x3q2-h9hx-4r4j"],"references":[{"url":"https://github.com/docling-project/docling/commit/38b6fa0a465d46fdacbbec333f50fa19c4f6b342","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/pull/4419","type":"patch","title":"OSV fix"},{"url":"https://github.com/docling-project/docling/releases/tag/v2.132.0","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling/security/advisories/GHSA-x3q2-h9hx-4r4j","type":"patch","title":"OSV fix"},{"url":"https://osv.dev/vulnerability/GHSA-x3q2-h9hx-4r4j","type":"advisory","title":"OSV GHSA-x3q2-h9hx-4r4j"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105744","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/docling-project/docling","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/PYSEC-2026-4191","type":"advisory","title":"OSV PYSEC-2026-4191"}],"epssScore":0.00344,"epssPercentile":0.25873,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T22:16:57.177Z","addedAt":"2026-10-05T23:50:40.372Z","updatedAt":"2026-10-08T12:42:40.390Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105744","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105744","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X3Q2-H9HX-4R4J"}]},{"id":"86fc4196-3c36-4292-96eb-91bdef127066","slug":"cve-2026-103956","externalId":"CVE-2026-103956","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103956 — Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-ad…","description":"Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured.\n\n\n\nTo remediate this issue, users should upgrade to version 1.6.1 or later.","cveId":"CVE-2026-103956","cvssScore":10,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-306","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-124-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/loom/releases/tag/v1.6.1","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/loom/security/advisories/GHSA-vgmj-998f-r8mp","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":0.00468,"epssPercentile":0.38529,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T19:16:39.750Z","addedAt":"2026-10-02T19:50:41.895Z","updatedAt":"2026-10-06T15:50:55.696Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103956","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103956","note":"authoritative record"}]},{"id":"03b54eb3-095b-4132-bda6-723ead79da8e","slug":"cve-2026-85086","externalId":"CVE-2026-85086","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85086 — Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.","description":"Improper certificate validation, Initialization of a resource with an insecure default vulnerability in Apache Thrift perl bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85086","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-295","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/c7f9g4027ok0gocyso2y84r2mhgc2xmy","type":"advisory","title":"security@apache.org"}],"epssScore":0.0026,"epssPercentile":0.16226,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T12:17:21.490Z","addedAt":"2026-10-02T13:50:40.767Z","updatedAt":"2026-10-02T19:50:41.366Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85086","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85086","note":"authoritative record"}]},{"id":"f3231a65-aa82-4b1d-beb9-20e536084cd7","slug":"cve-2026-85494","externalId":"CVE-2026-85494","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85494 — Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size …","description":"Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-85494","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-248","CWE-407","CWE-789","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/rm0m34gt6fh1flvt16wty559hfg191qr","type":"advisory","title":"security@apache.org"}],"epssScore":0.00467,"epssPercentile":0.38463,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T11:17:36.010Z","addedAt":"2026-10-02T11:50:39.855Z","updatedAt":"2026-10-08T00:39:29.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85494","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85494","note":"authoritative record"}]},{"id":"fabf8ee6-e07e-475a-8c05-ae4e048e0c09","slug":"cve-2026-94634","externalId":"CVE-2026-94634","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94634 — Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python b…","description":"Allocation of resources without limits or throttling, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python bindings.\n\n\n\nThis issue affects Apache Thrift: before 0.25.0.\n\n\n\nUsers are recommended to upgrade to version 0.25.0, which fixes the issue.","cveId":"CVE-2026-94634","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-770","CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/33otcgbqd27wf6qq810q56znzbomnhg1","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread/dgy8ox9t4bh1xhf74ovf29ht87x7dno4","type":"advisory","title":"security@apache.org"}],"epssScore":0.00426,"epssPercentile":0.3484,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T10:17:09.467Z","addedAt":"2026-10-02T11:50:39.788Z","updatedAt":"2026-10-02T15:50:40.603Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94634","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94634","note":"authoritative record"}]},{"id":"2904e55a-899c-434a-9028-24f6240f23d3","slug":"cve-2026-71448","externalId":"CVE-2026-71448","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71448 — : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.","description":": Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.\n\nThis issue affects EasyIO FS32: before 3.0b63.","cveId":"CVE-2026-71448","cvssScore":5.6,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories","type":"advisory","title":"productsecurity@jci.com"}],"epssScore":0.00148,"epssPercentile":0.03484,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:04.753Z","addedAt":"2026-10-01T23:50:39.669Z","updatedAt":"2026-10-02T21:50:40.101Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71448","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71448","note":"authoritative record"}]},{"id":"b7ddf62e-ba28-4952-aa05-5877eb4a91e0","slug":"cve-2026-100260","externalId":"CVE-2026-100260","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100260 — In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset","description":"In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset","cveId":"CVE-2026-100260","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":"jetbrains","product":"youtrack","affectedVersions":["< 2026.2.18991"],"cwes":["CWE-1188"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.jetbrains.com/privacy-security/issues-fixed/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00265,"epssPercentile":0.16915,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:16:56.827Z","addedAt":"2026-09-30T17:50:47.659Z","updatedAt":"2026-10-02T21:50:39.980Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100260","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100260","note":"authoritative record"}]},{"id":"9936b6c0-e9d0-4044-b811-765381f961f3","slug":"cve-2026-100291","externalId":"CVE-2026-100291","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100291 — In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authenti…","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.","cveId":"CVE-2026-100291","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00331,"epssPercentile":0.24186,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T20:17:09.300Z","addedAt":"2026-09-29T21:50:42.386Z","updatedAt":"2026-09-29T23:50:39.164Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100291","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100291","note":"authoritative record"}]},{"id":"bbd296a4-d8e9-45d6-b14c-a8f4f78756ea","slug":"cve-2026-102676","externalId":"CVE-2026-102676","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102676 — Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS.","description":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.","cveId":"CVE-2026-102676","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"electron","affectedVersions":["pkg:npm/electron < 41.10.6","pkg:npm/electron >= 42.0.0-alpha.1, < 42.9.2","pkg:npm/electron >= 43.0.0-alpha.1, < 43.4.1","pkg:npm/electron >= 44.0.0-alpha.1, < 44.0.0-beta.5"],"cwes":["CWE-269","CWE-1188"],"tags":["nvd","status:received","osv","osv:ghsa-9qh4-3jw8-366w","ecosystem:npm","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/electron/electron/commit/6462a2e1dc4e6adffd3b7d9b9be1474c45dcbbe2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/9a675aef8822bae4088567822969f900b3a37671","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/b3ae0aab5cf81c2ed03d04df1ae8e69ecfab7886","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/commit/cd34f335c8664613db5b6e61ae51e2e1846233ae","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v41.10.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v42.9.2","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v43.4.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/releases/tag/v44.0.0-beta.5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/electron/electron/security/advisories/GHSA-9qh4-3jw8-366w","type":"advisory","title":"security-advisories@github.com"},{"url":"https://osv.dev/vulnerability/GHSA-9qh4-3jw8-366w","type":"advisory","title":"OSV GHSA-9qh4-3jw8-366w"},{"url":"https://github.com/electron/electron","type":"vendor","title":"OSV package"}],"epssScore":0.00451,"epssPercentile":0.37179,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T17:17:07.973Z","addedAt":"2026-09-29T17:50:40.772Z","updatedAt":"2026-09-30T19:50:42.889Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102676","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102676","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9QH4-3JW8-366W"}]},{"id":"73a947d4-7047-4492-9fd8-098f3d1f2bdc","slug":"cve-2026-73596","externalId":"CVE-2026-73596","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-73596 — Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default v…","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.","cveId":"CVE-2026-73596","cvssScore":3.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","type":"advisory","title":"security_alert@emc.com"}],"epssScore":0.00175,"epssPercentile":0.06327,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T12:17:11.557Z","addedAt":"2026-09-29T13:50:39.304Z","updatedAt":"2026-09-30T05:50:39.428Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73596","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-73596","note":"authoritative record"}]},{"id":"337c32bc-fd9b-4f9f-bab8-62cae52cc44f","slug":"cve-2026-101064","externalId":"CVE-2026-101064","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-101064 — Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify …","description":"Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials.","cveId":"CVE-2026-101064","cvssScore":8.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"Go","product":"github.com/obot-platform/obot","affectedVersions":["pkg:golang/github.com/obot-platform/obot < 0.23.0"],"cwes":["CWE-918","CWE-1188"],"tags":["nvd","status:received","osv","osv:ghsa-jgh3-fggc-mcpm","ecosystem:go","osv:go-2026-6522","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/obot-before-0.23.0-server-side-request-forgery-via-mcp","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-jgh3-fggc-mcpm","type":"advisory","title":"OSV GHSA-jgh3-fggc-mcpm"},{"url":"https://github.com/obot-platform/obot","type":"vendor","title":"OSV package"},{"url":"https://github.com/obot-platform/obot/releases/tag/v0.23.0","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GO-2026-6522","type":"advisory","title":"OSV GO-2026-6522"}],"epssScore":0.00243,"epssPercentile":0.14196,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-27T21:17:01.893Z","addedAt":"2026-09-27T21:50:37.997Z","updatedAt":"2026-09-28T21:50:39.247Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101064","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-101064","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-JGH3-FGGC-MCPM"}]},{"id":"a64cb1a3-55b1-4671-be9a-2780f0cc4a59","slug":"cve-2026-93354","externalId":"CVE-2026-93354","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93354 — Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth …","description":"Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.","cveId":"CVE-2026-93354","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Gimanh/taskview-community/releases/tag/v1.56.0","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/taskview-community-missing-authentication-via-oauth-dynamic-client-registration","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00265,"epssPercentile":0.1691,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T20:17:34.613Z","addedAt":"2026-09-24T21:50:44.717Z","updatedAt":"2026-10-05T21:50:40.375Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93354","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93354","note":"authoritative record"}]},{"id":"b30cf245-2569-4da5-bac1-c59d07286dbb","slug":"cve-2026-97055","externalId":"CVE-2026-97055","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-97055 — SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the de…","description":"SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user — including an administrator — by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque.","cveId":"CVE-2026-97055","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-1188"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/SigNoz/signoz/commit/67895d366d","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/SigNoz/signoz/commit/b02aae2db3","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/SigNoz/signoz/security/advisories/GHSA-c26w-g4j8-39m2","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.vulncheck.com/advisories/signoz-before-0.143.0-authentication-bypass-via-empty-jwt-secret","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00406,"epssPercentile":0.32796,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T02:16:54.333Z","addedAt":"2026-09-24T03:50:37.149Z","updatedAt":"2026-09-24T21:50:44.107Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97055","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-97055","note":"authoritative record"}]},{"id":"4124403b-44c9-4aea-b312-f59b26f0d111","slug":"cve-2026-86246","externalId":"CVE-2026-86246","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86246 — Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default  including ALLOW_CL…","description":"Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default  including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.\n\n\n\nThis issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue.","cveId":"CVE-2026-86246","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"critical","vendor":"apache","product":"tomcat native","affectedVersions":[">= 1.3.0, < 1.3.9",">= 2.0.0, < 2.0.16"],"cwes":["CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol","type":"vendor","title":"Vendor Advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/32","type":"advisory","title":"Mailing List"}],"epssScore":0.00361,"epssPercentile":0.27809,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T13:17:31.117Z","addedAt":"2026-09-23T13:50:38.811Z","updatedAt":"2026-10-06T15:50:55.380Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86246","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86246","note":"authoritative record"}]},{"id":"b4c28c88-7e83-405b-a502-82932ad421ed","slug":"cve-2026-89139","externalId":"CVE-2026-89139","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89139 — Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess…","description":"Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are taken from the compute provider configuration supplied in the caller's request rather than from operator configuration. An authenticated caller holding only a write role in a single namespace can therefore configure a worker deployment version so that the Worker Service executes a command of the caller's choosing on its own host, under the account the server process runs as. Execution is immediate rather than deferred: the configuration handler invokes every provider using the invoke strategy directly after validating the submitted specification, so no scaling decision, task arrival, or unusual request sequence is required. Because the Worker Service process holds the persistence credentials for every namespace in the cluster and the cluster's TLS material, the consequence reaches beyond the caller's namespace to the cluster as a whole. The provider is present in the official temporal-server binaries and container images for the affected releases. The only control that can keep it unreachable is the compute provider allowlist, the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled, and that control does not deny by default: its default value is an unset list, and the allowlist check is skipped entirely when the value is unset, so every registered compute provider is permitted, this one included. To determine whether a deployment is affected, check the following together. The deployed Temporal Server version is 1.31.0 or later and earlier than 1.31.3. The Worker Service is running, which it is in the default service set and therefore in a stock deployment. The effective per-namespace value of workercontroller.compute_providers.enabled is either unset or contains subprocess. And authorization is configured, meaning a real authorizer and claim mapper are in place; a deployment running with no authorizer already grants every caller unrestricted access to every namespace, so it has no namespace boundary for this to cross. Note that the separate per-namespace dynamic configuration setting workercontroller.enabled does not gate the affected path. It defaults to false, and a deployment that has never set it in any namespace is still affected, which was confirmed by running an affected release with no value for that setting present anywhere in dynamic configuration. To look for a compute configuration that is already attached, call DescribeWorkerDeploymentVersion for each worker deployment version in each namespace and check whether any scaling group's compute provider type is subprocess.","cveId":"CVE-2026-89139","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-78","CWE-749","CWE-1188"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/temporalio/temporal-auto-scaled-workers/pull/129","type":"advisory","title":"security@temporal.io"},{"url":"https://github.com/temporalio/temporal/pull/12021","type":"advisory","title":"security@temporal.io"},{"url":"https://github.com/temporalio/temporal/releases/tag/v1.31.3","type":"advisory","title":"security@temporal.io"},{"url":"https://github.com/temporalio/temporal/releases/tag/v1.32.0","type":"advisory","title":"security@temporal.io"}],"epssScore":0.00581,"epssPercentile":0.46048,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T12:17:24.440Z","addedAt":"2026-09-21T13:50:39.521Z","updatedAt":"2026-09-22T19:50:40.555Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89139","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89139","note":"authoritative record"}]},{"id":"2dbed790-5085-40bd-8baf-ff80627a354f","slug":"ghsa-jgh3-fggc-mcpm","externalId":"GHSA-jgh3-fggc-mcpm","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Obot: Server-Side Request Forgery via remote MCP server URL","description":"## Summary\n\nIn affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (`169.254.169.254`), so a use with the Power User, Power User Plus, or Admin role can coerce Obot into making requests to internal services and to the cloud instance metadata service, and read the responses.\n\n## Am I affected?\n\nYou are affected if you run Obot `<= v0.22.1` with authentication enabled and allow privileged users (with the Power User or higher privileges) to register remote MCP servers . The metadata-sync code path that triggers the fetch runs automatically during reconciliation, so no user interaction beyond registration is required.\n\n## Details\n\nA remote server's URL (`RemoteRuntimeConfig.URL`) is accepted at registration after only checking that it is parseable and uses an `http`/`https` scheme — the destination is never constrained. Obot then connects to that URL when the server is launched or its OAuth state is checked, and the controller automatically fetches OAuth discovery metadata from it during reconcile. The one egress guard that exists (`DisallowLocalhostMCP`) is disabled by default, only blocks loopback when enabled, and is absent from the automatic metadata-fetch path. Because the fetched response body is reflected back in Obot's error messages, this is a non-blind SSRF.\n\n## Impact\n\nAn attacker can reach internal-only services and the cloud metadata service if they have the Power User, Power User Plus, or Admin role. Against `169.254.169.254` this can disclose the host's cloud IAM credentials, enabling a pivot into the cloud account.\n\n## Mitigation\n\nUpgrade to **v0.23.0** or later, which applies a single outbound egress chokepoint — rejecting loopback, link-local (including `169.254.169.254`), RFC1918, and IPv6 ULA on the resolved IP at dial time — uniformly across the remote-MCP client and the OAuth-metadata client.\n\n## Severity\n\nCVSS v3.1 Score: **7.6/10 (High)** — `CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N`\n\n## Credits\n\nThe Obot team would like to thank HE WEI（ギカク）(https://www.linkedin.com/in/gikaku, [@hewei-gikaku](https://github.com/hewei-gikaku)) for responsibly disclosing this issue in accordance with our [security policy](https://github.com/obot-platform/obot/?tab=security-ov-file).","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N","severity":"high","vendor":"Go","product":"github.com/obot-platform/obot","affectedVersions":["pkg:golang/github.com/obot-platform/obot < 0.23.0"],"cwes":["CWE-1188","CWE-918"],"tags":["osv","osv:ghsa-jgh3-fggc-mcpm","ecosystem:go"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-jgh3-fggc-mcpm","type":"advisory","title":"OSV GHSA-jgh3-fggc-mcpm"},{"url":"https://github.com/obot-platform/obot/security/advisories/GHSA-jgh3-fggc-mcpm","type":"other","title":"OSV web"},{"url":"https://github.com/obot-platform/obot","type":"vendor","title":"OSV package"},{"url":"https://github.com/obot-platform/obot/releases/tag/v0.23.0","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-18T17:59:46.000Z","addedAt":"2026-09-18T19:54:28.834Z","updatedAt":"2026-09-18T19:54:28.834Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-jgh3-fggc-mcpm"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-jgh3-fggc-mcpm"}]}],"pagination":{"page":1,"limit":20,"total":102,"totalPages":6,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:47:47.390Z","durationMs":20,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-1188"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}