{"success":true,"data":{"threats":[{"id":"5cb82945-9f1a-49b7-aa82-d67c549a60ba","slug":"cve-2026-84245","externalId":"CVE-2026-84245","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84245 — IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component.","description":"IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.","cveId":"CVE-2026-84245","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.313Z","addedAt":"2026-10-08T21:05:53.514Z","updatedAt":"2026-10-08T21:05:53.514Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84245","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84245","note":"authoritative record"}]},{"id":"2e0ced55-fd0d-42e1-b44c-141042bc9904","slug":"cve-2026-50054","externalId":"CVE-2026-50054","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-50054 — An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant anothe…","description":"An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.","cveId":"CVE-2026-50054","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories","type":"advisory","title":"cve@rapid7.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T17:17:17.180Z","addedAt":"2026-10-08T18:39:31.781Z","updatedAt":"2026-10-08T21:05:51.518Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50054","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-50054","note":"authoritative record"}]},{"id":"9b6010f3-d801-48a5-8ad3-e4df20a005c1","slug":"cve-2026-93017","externalId":"CVE-2026-93017","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93017 — The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or …","description":"The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.\n\nRef: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373\n```\n- apiGroups:\n  - \"\"\n  resources:\n  - secrets\n  verbs:\n  - get\n  - list\n```\n\nBy spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace.\n\n```\nspec:\n serviceAccountName:\"gather\"\n```","cveId":"CVE-2026-93017","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93017","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515741","type":"advisory","title":"secalert@redhat.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:56.950Z","addedAt":"2026-10-08T16:39:35.972Z","updatedAt":"2026-10-08T21:05:50.579Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93017","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93017","note":"authoritative record"}]},{"id":"ba5e1a18-54bb-4a96-a783-f43d712867a7","slug":"cve-2026-107510","externalId":"CVE-2026-107510","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107510 — An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","description":"An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.","cveId":"CVE-2026-107510","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-88","CWE-269","CWE-284"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.infoblox.com/s/article/Security-Advisory-NIOS-Maintenance-Mode-Permits-Root-Shell","type":"advisory","title":"f84ca5ce-fbe7-4668-8724-994599108a02"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T10:17:09.553Z","addedAt":"2026-10-08T10:39:34.992Z","updatedAt":"2026-10-08T23:06:37.387Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107510","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107510","note":"authoritative record"}]},{"id":"7555d540-cb5d-4856-8e64-937fb9db58f5","slug":"cve-2026-103692","externalId":"CVE-2026-103692","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103692 — The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated user…","description":"The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.","cveId":"CVE-2026-103692","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/d2341538-77fa-48a0-83e3-bc9a3818276c/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00146,"epssPercentile":0.03352,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T06:16:38.323Z","addedAt":"2026-10-08T06:39:29.614Z","updatedAt":"2026-10-08T21:05:46.721Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103692","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103692","note":"authoritative record"}]},{"id":"29d82a1b-2a5b-4179-8dd5-5a3c7dced348","slug":"cve-2026-94578","externalId":"CVE-2026-94578","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94578 — Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) in…","description":"Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated users to gain root-equivalent chassis access controls. By returning specific, crafted Vendor-Specific Attributes (VSAs) or directory claims from an external identity provider (such as RADIUS, LDAP, TACACS+, or Federated IDP), an account can bypass administrative role restriction checks during session establishment.","cveId":"CVE-2026-94578","cvssScore":7.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39150","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00236,"epssPercentile":0.1342,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:37.840Z","addedAt":"2026-10-08T04:39:32.982Z","updatedAt":"2026-10-08T21:05:45.760Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94578","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94578","note":"authoritative record"}]},{"id":"3e397235-5be2-4d51-bf51-fd570a6ffa33","slug":"cve-2026-87681","externalId":"CVE-2026-87681","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87681 — An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1.","description":"An Access Control Bypass vulnerability exists in the Role-Based Access Control (RBAC) validation engine of Brocade Fabric OS versions before 10.0.1. When processing certain management protocol operations, the RBAC engine incorrectly categorizes non-standard action opcodes during permission checks. This allows authenticated users with read-only management privileges to bypass access controls and execute restricted administrative operations.","cveId":"CVE-2026-87681","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39075","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00172,"epssPercentile":0.06064,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T01:16:32.620Z","addedAt":"2026-10-08T02:39:29.925Z","updatedAt":"2026-10-08T21:05:45.348Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87681","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87681","note":"authoritative record"}]},{"id":"cb565d71-8af0-4193-8a0a-43436e30b4cb","slug":"cve-2026-76266","externalId":"CVE-2026-76266","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76266 — In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Spl…","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installation content when it performs upgrade operations with root privileges. The vulnerability requires an affected Linux package upgrade to occur after the local user modifies the installation. The local user should not be able to elevate privileges at will.","cveId":"CVE-2026-76266","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","type":"advisory","title":"psirt@cisco.com"}],"epssScore":0.00124,"epssPercentile":0.0187,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T21:17:17.310Z","addedAt":"2026-10-07T22:39:36.586Z","updatedAt":"2026-10-08T21:05:44.135Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76266","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76266","note":"authoritative record"}]},{"id":"24b2bedf-1890-4953-9b6c-c7b1814d65a4","slug":"cve-2026-46434","externalId":"CVE-2026-46434","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-46434 — wger is a free, open-source workout and fitness manager.","description":"wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequiredMixin`), and performs no privilege-hierarchy check to prevent a lower-privileged role from disabling a higher-privileged one. Version 2.6 fixes the issue.","cveId":"CVE-2026-46434","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","severity":"high","vendor":"PyPI","product":"wger","affectedVersions":["pkg:pypi/wger <= 2.1"],"cwes":["CWE-269"],"tags":["nvd","status:received","status:deferred","osv","osv:ghsa-x249-cx55-2h87","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/wger-project/wger/releases/tag/2.6","type":"other","title":"OSV web"},{"url":"https://github.com/wger-project/wger/security/advisories/GHSA-x249-cx55-2h87","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-x249-cx55-2h87","type":"advisory","title":"OSV GHSA-x249-cx55-2h87"},{"url":"https://github.com/wger-project/wger","type":"vendor","title":"OSV package"}],"epssScore":0.00221,"epssPercentile":0.1159,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:10.277Z","addedAt":"2026-10-07T14:39:35.259Z","updatedAt":"2026-10-07T18:42:45.436Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46434","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-46434","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X249-CX55-2H87"}]},{"id":"96faa22c-56e1-4559-88b5-63db2e6dda10","slug":"cve-2026-73802","externalId":"CVE-2026-73802","source":"OSV","sourceType":"osv","type":"vulnerability","title":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner","description":"gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled in gitea.com/gitea/runner","cveId":"CVE-2026-73802","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":"Go","product":"gitea.com/gitea/runner","affectedVersions":["pkg:golang/gitea.com/gitea/runner < 1.0.9-0.20260731160927-34bfa1915022"],"cwes":["CWE-269"],"tags":["osv","osv:ghsa-x4q3-gcj3-m6cf","ecosystem:go","osv:go-2026-6656"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-x4q3-gcj3-m6cf","type":"advisory","title":"OSV GHSA-x4q3-gcj3-m6cf"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf","type":"advisory","title":"OSV advisory"},{"url":"https://gitea.com/gitea/runner/pulls/1058","type":"other","title":"OSV web"},{"url":"https://gitea.com/gitea/runner/releases/tag/v3.0.0","type":"other","title":"OSV web"},{"url":"https://github.com/go-gitea/gitea","type":"vendor","title":"OSV package"},{"url":"https://osv.dev/vulnerability/GO-2026-6656","type":"advisory","title":"OSV GO-2026-6656"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:10:14.000Z","addedAt":"2026-10-03T01:54:23.247Z","updatedAt":"2026-10-07T18:42:44.160Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73802","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-73802","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-X4Q3-GCJ3-M6CF"}]},{"id":"b657f972-8fda-4fca-b0d2-fb1fab378d26","slug":"cve-2026-87782","externalId":"CVE-2026-87782","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87782 — The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with…","description":"The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.","cveId":"CVE-2026-87782","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/0f3af398-4a70-4987-9da8-b876b9e932c7/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00232,"epssPercentile":0.1291,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T07:17:01.847Z","addedAt":"2026-10-07T08:39:33.432Z","updatedAt":"2026-10-07T16:39:31.880Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87782","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87782","note":"authoritative record"}]},{"id":"9eaa8f2e-01cb-4d68-ba1d-3402716449e0","slug":"cve-2026-106492","externalId":"CVE-2026-106492","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106492 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.","cveId":"CVE-2026-106492","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","severity":"high","vendor":"npm","product":"@backstage/backend-defaults","affectedVersions":["pkg:npm/%40backstage/backend-defaults < 0.17.8"],"cwes":["CWE-269","CWE-863"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-cq7v-rfgc-5c7v","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/40346245c53e1bf26dee56601e95c5c4ab9cc124","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/bc80ffdafbc92ff7b8c72347eace13cb8688fd33","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-cq7v-rfgc-5c7v","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cq7v-rfgc-5c7v","type":"advisory","title":"OSV GHSA-cq7v-rfgc-5c7v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106492","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00238,"epssPercentile":0.13678,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:18.220Z","addedAt":"2026-10-06T22:39:33.031Z","updatedAt":"2026-10-07T18:42:42.946Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106492","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106492","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CQ7V-RFGC-5C7V"}]},{"id":"14266515-46f1-4509-b734-25e2b1f6e60b","slug":"cve-2026-79813","externalId":"CVE-2026-79813","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79813 — A local privilege escalation vulnerability exists in the ClearPass client software.","description":"A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met.","cveId":"CVE-2026-79813","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00083,"epssPercentile":0.00224,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:32.967Z","addedAt":"2026-10-06T20:39:33.408Z","updatedAt":"2026-10-08T04:39:32.543Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79813","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79813","note":"authoritative record"}]},{"id":"c2fd051e-0cb3-4728-b793-6fa2e542aace","slug":"cve-2026-79806","externalId":"CVE-2026-79806","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79806 — A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate…","description":"A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.","cveId":"CVE-2026-79806","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00098,"epssPercentile":0.00734,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:32.133Z","addedAt":"2026-10-06T20:39:33.354Z","updatedAt":"2026-10-08T04:39:32.502Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79806","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79806","note":"authoritative record"}]},{"id":"09bc9127-c0e8-4880-9a84-7e5f7668eb64","slug":"cve-2026-76748","externalId":"CVE-2026-76748","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76748 — A privilege escalation vulnerability exists in the API of AOS-S.","description":"A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.","cveId":"CVE-2026-76748","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05156en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00275,"epssPercentile":0.18266,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:30.173Z","addedAt":"2026-10-06T20:39:33.221Z","updatedAt":"2026-10-08T04:39:32.386Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76748","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76748","note":"authoritative record"}]},{"id":"7c75376c-fbc5-4dce-ada7-2a41fd3acdcd","slug":"cve-2026-76742","externalId":"CVE-2026-76742","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76742 — Authentication bypass vulnerabilities exist in the web management interface of AOS-S.","description":"Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.","cveId":"CVE-2026-76742","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05156en_us&docLocale=en_US","type":"advisory","title":"security-alert@hpe.com"}],"epssScore":0.00586,"epssPercentile":0.46324,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:29.490Z","addedAt":"2026-10-06T20:39:33.173Z","updatedAt":"2026-10-08T04:39:32.355Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76742","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76742","note":"authoritative record"}]},{"id":"fda7b043-49c0-4aac-9254-8f4f81102dee","slug":"cve-2026-55307","externalId":"CVE-2026-55307","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55307 — In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code.","description":"In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-55307","cvssScore":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01","type":"advisory","title":"dsap-vuln-management@google.com"}],"epssScore":0.00074,"epssPercentile":0.00068,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:14.633Z","addedAt":"2026-10-06T20:39:32.480Z","updatedAt":"2026-10-06T20:39:32.480Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55307","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55307","note":"authoritative record"}]},{"id":"3e8cbfd8-8132-43d4-bc1e-b4691b7f4b7f","slug":"cve-2026-106296","externalId":"CVE-2026-106296","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106296 — Improper privilege management in UI in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to by…","description":"Improper privilege management in UI in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","cveId":"CVE-2026-106296","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-269"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/540078886","type":"advisory","title":"Permissions Required"}],"epssScore":0.00159,"epssPercentile":0.04403,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:57.573Z","addedAt":"2026-10-06T20:39:31.400Z","updatedAt":"2026-10-08T18:39:30.299Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106296","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106296","note":"authoritative record"}]},{"id":"46fd5199-1be5-4735-8f5f-df90e7ccb777","slug":"cve-2026-67269","externalId":"CVE-2026-67269","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67269 — Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerSto…","description":"Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.","cveId":"CVE-2026-67269","cvssScore":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"critical","vendor":"dell","product":"container storage modules","affectedVersions":["< 1.18.0"],"cwes":["CWE-269"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00534,"epssPercentile":0.43282,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:17:19.130Z","addedAt":"2026-10-06T15:51:00.502Z","updatedAt":"2026-10-08T18:39:30.142Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67269","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67269","note":"authoritative record"}]},{"id":"e278e939-22cd-4c15-8f63-8fc916ee5c14","slug":"cve-2026-105688","externalId":"CVE-2026-105688","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105688 — Penpot is an open-source design and prototyping platform.","description":"Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.","cveId":"CVE-2026-105688","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-269"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/penpot/penpot/commit/5efd9cc3c5689485322f57b644b83a3bd2e33cee","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/penpot/penpot/releases/tag/2.18.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/penpot/penpot/security/advisories/GHSA-mx4v-cmxq-644v","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":0.00264,"epssPercentile":0.16854,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T20:17:18.193Z","addedAt":"2026-10-05T21:50:41.023Z","updatedAt":"2026-10-06T15:50:58.516Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105688","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105688","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":1047,"totalPages":53,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:17:44.590Z","durationMs":42,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-269"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}