{"success":true,"data":{"threats":[{"id":"53d60297-e6a8-49ab-a76e-df7d5397e0b3","slug":"cve-2026-104075","externalId":"CVE-2026-104075","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104075 — TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management …","description":"TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.","cveId":"CVE-2026-104075","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://code-white.com/public-vulnerability-list/#authentication-bypass-in-tvu-receiver-transceiver-web-management-interface","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tvu-networks-receiver-transceiver-authentication-bypass-via-tvu-login","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:29.377Z","addedAt":"2026-10-08T21:05:52.754Z","updatedAt":"2026-10-08T23:06:39.242Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104075","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104075","note":"authoritative record"}]},{"id":"96408b06-7fc5-4c20-87a0-73fc7868d74a","slug":"cve-2026-107361","externalId":"CVE-2026-107361","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107361 — The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0…","description":"The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from any IP address (userAuthIps=::,0.0.0.0/0) and auto-creates users with full access. The passwordSecret is hardcoded to the public value \"Malcolm\". A network-adjacent attacker bypasses nginx entirely by connecting directly to port 8005 with a forged identity header.","cveId":"CVE-2026-107361","cvssScore":4.2,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/Malcolm/security/advisories/GHSA-86h3-7rf8-8j34","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T18:17:21.170Z","addedAt":"2026-10-08T18:39:31.867Z","updatedAt":"2026-10-08T23:06:38.754Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107361","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107361","note":"authoritative record"}]},{"id":"4455af7c-d8b2-4b62-a3a8-04a2160dc54f","slug":"cve-2026-94585","externalId":"CVE-2026-94585","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94585 — An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 pla…","description":"An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 platform. An unauthenticated, network-adjacent attacker can exploit an unauthenticated endpoint within the Single Sign-On (SSO) workflow to gain administrative access to the device management interface.","cveId":"CVE-2026-94585","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39134","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00167,"epssPercentile":0.05405,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T05:17:06.523Z","addedAt":"2026-10-08T06:39:29.575Z","updatedAt":"2026-10-08T21:05:46.606Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94585","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94585","note":"authoritative record"}]},{"id":"0d2a2130-a752-48e4-8972-1804b70fb3e3","slug":"cve-2026-107194","externalId":"CVE-2026-107194","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107194 — Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via \"login_type\":\"5\" in a login request, potentially leading to \"…","description":"Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via \"login_type\":\"5\" in a login request, potentially leading to \"local blackouts on the whole continent\" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.","cveId":"CVE-2026-107194","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jakkaru.de/articles/sungrow-vulnerability-exposes-gigawatts-worldwide","type":"advisory","title":"cve@mitre.org"},{"url":"https://www.sungrowpower.com/en/products/cloud-software/isolarcloud","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00342,"epssPercentile":0.25681,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.203Z","addedAt":"2026-10-07T14:39:35.212Z","updatedAt":"2026-10-07T16:39:32.238Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107194","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107194","note":"authoritative record"}]},{"id":"d2d901e7-0ffb-4c53-ad08-60104fbb7a88","slug":"cve-2026-19572","externalId":"CVE-2026-19572","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19572 — A security vulnerability has been identified in FlexNet Publisher lmadmin.","description":"A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials.","cveId":"CVE-2026-19572","cvssScore":9.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://community.revenera.com/s/article/CVE202619572-FlexNet-Publisher-lmadmin-SOAP-Authentication-Bypass-Vulnerability","type":"advisory","title":"PSIRT-CNA@flexerasoftware.com"}],"epssScore":0.00372,"epssPercentile":0.29021,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T04:18:09.053Z","addedAt":"2026-10-07T04:39:33.993Z","updatedAt":"2026-10-07T20:39:40.028Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19572","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19572","note":"authoritative record"}]},{"id":"1a8109a4-b7d9-4d42-bb7e-86ff17c1b652","slug":"cve-2026-39793","externalId":"CVE-2026-39793","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-39793 — Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.","description":"Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.","cveId":"CVE-2026-39793","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/simple-jwt-login/vulnerability/wordpress-simple-jwt-login-plugin-4-0-0-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00423,"epssPercentile":0.34579,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:52.237Z","addedAt":"2026-10-06T09:50:44.013Z","updatedAt":"2026-10-06T15:50:59.945Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39793","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-39793","note":"authoritative record"}]},{"id":"4f35931b-5d39-4333-8c7b-a91faa1a40c8","slug":"cve-2026-39769","externalId":"CVE-2026-39769","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-39769 — Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.","description":"Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.","cveId":"CVE-2026-39769","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/graphina-elementor-charts-and-graphs/vulnerability/wordpress-graphina-plugin-3-1-12-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00485,"epssPercentile":0.39774,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:49.280Z","addedAt":"2026-10-06T09:50:43.913Z","updatedAt":"2026-10-06T15:50:59.844Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39769","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-39769","note":"authoritative record"}]},{"id":"c80f88e4-75cd-444f-ad78-70dcc1e1a843","slug":"cve-2026-100518","externalId":"CVE-2026-100518","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100518 — Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.","description":"Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.","cveId":"CVE-2026-100518","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/advanced-google-recaptcha/vulnerability/wordpress-advanced-google-recaptcha-plugin-5-40-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00256,"epssPercentile":0.15852,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T09:17:37.283Z","addedAt":"2026-10-06T09:50:43.357Z","updatedAt":"2026-10-06T15:50:59.421Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100518","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100518","note":"authoritative record"}]},{"id":"152df708-01ee-4c96-b911-5815b0131110","slug":"cve-2026-100261","externalId":"CVE-2026-100261","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100261 — In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission","description":"In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission","cveId":"CVE-2026-100261","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":"jetbrains","product":"youtrack","affectedVersions":["< 2026.2.18991"],"cwes":["CWE-288"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.jetbrains.com/privacy-security/issues-fixed/","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00175,"epssPercentile":0.0637,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T16:16:56.970Z","addedAt":"2026-09-30T17:50:47.664Z","updatedAt":"2026-10-02T21:50:39.988Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100261","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100261","note":"authoritative record"}]},{"id":"5bc1045c-dfa6-428a-83ee-e4a3bc224a39","slug":"ghsa-9c5c-9qcx-q35q","externalId":"GHSA-9c5c-9qcx-q35q","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets","description":"| Field | Value |\n| --- | --- |\n| Ecosystem | npm |\n| Package | `@nestjs/platform-fastify` |\n| Affected versions | `>= 12.0.0, < 12.0.2` and `< 11.2.4` |\n| Patched versions | `12.0.2` and `11.2.4` (upgrade to `12.0.3` / `11.2.5`) |\n\n### Summary\n\nOn the Fastify adapter, an HTTP request that uses an **absolute-form request target** (`GET http://host/path HTTP/1.1`\ninstead of `GET /path HTTP/1.1`) reaches the route handler without running the path-scoped Nest middleware bound to\nthat route. Applications that enforce authentication or authorization in middleware execute the protected handler\nwith those checks skipped.\n\n### Impact\n\nAny application that\n\n- uses `@nestjs/platform-fastify`, and\n- binds middleware to specific paths via `MiddlewareConsumer.forRoutes(...)` or `.exclude(...)`, and\n- is reachable by a client that controls the raw request line.\n\nNode's HTTP server accepts absolute-form targets, so no special server configuration is needed. Exposure is reduced\nwhen a reverse proxy in front of the application rewrites the request target to origin-form, which most do.\n\nWhere the bypassed middleware performs authentication or authorization, the result is an authentication or\nauthorization bypass. Where it performs logging, rate limiting or body handling, those are silently skipped instead.\n\n### Details\n\nFastify's router (`find-my-way`) resolves an absolute-form target to its path before matching, so the route handler\nis dispatched normally. Two places on the middleware side matched against the **raw** request target instead:\n\n1. The bundled copy of the `@fastify/middie` engine at `packages/platform-fastify/adapters/middie/fastify-middie.ts`.\n   NestJS carried this fork to apply an earlier path-decoding fix and it did not track the upstream absolute-form fix\n   released in `@fastify/middie@9.3.4`.\n2. `FastifyAdapter`'s own re-check in `createMiddlewareFactory()`, which tests the middleware path regexp against\n   `req.originalUrl`.\n\nBoth normalized and percent-decoded the target, but neither resolved absolute-form to a path, so the router and the\nmiddleware layer disagreed about which path was being requested.\n\nA second, related defect contributed. Because the adapter always passes `routerOptions` (to install the version\nconstraint), Fastify did not reflect the deprecated **top-level** router options (`ignoreTrailingSlash`,\n`ignoreDuplicateSlashes`, `caseSensitive`, `useSemicolonDelimiter`) in `initialConfig.routerOptions`, which is what\nthe middleware engine reads. Applications passing those options at the top level had middleware normalize paths\ndifferently from the router, which widened the mismatch.\n\n### Proof of concept\n\n```ts\n@Controller('users')\nexport class UsersController {\n  @Get()\n  findAll() {\n    return 'protected data';\n  }\n}\n\n@Module({ controllers: [UsersController] })\nexport class AppModule implements NestModule {\n  configure(consumer: MiddlewareConsumer) {\n    consumer\n      .apply((req, res) => res.end('blocked by auth middleware'))\n      .forRoutes({ path: 'users', method: RequestMethod.GET });\n  }\n}\n```\n\n`supertest` and `light-my-request` always emit origin-form targets, so the request has to be written to the socket:\n\n```js\nconst { connect } = require('node:net');\n\nconst socket = connect(3000, '127.0.0.1', () => {\n  socket.write(\n    'GET http://127.0.0.1:3000/users HTTP/1.1\\r\\n' +\n      'Host: 127.0.0.1:3000\\r\\n' +\n      'Connection: close\\r\\n\\r\\n',\n  );\n});\nsocket.pipe(process.stdout);\n```\n\nObserved on an affected version: `protected data` — the middleware did not run.\nExpected, and observed on a patched version: `blocked by auth middleware`.\n\n### Patches\n\nFixed in **12.0.2** and **11.2.4**. Upgrading to **12.0.3** or **11.2.5** is recommended.\n\n- The bundled `@fastify/middie` fork was removed and the package now depends on `@fastify/middie@9.3.4`, which\n  resolves absolute-form targets before matching.\n- The adapter resolves absolute-form targets in its own route check, mirroring `find-my-way`.\n- Deprecated top-level Fastify router options are folded into `routerOptions` so the middleware engine and the\n  router normalize paths identically.\n\n### Workarounds\n\nIf you cannot upgrade, reject non-origin-form request targets before middleware runs. Register the hook on the\nFastify instance **before the application is initialized**, so that it runs ahead of the middleware engine's own\n`onRequest` hook, and confirm with the request above that the rejection takes effect:\n\n```ts\nconst adapter = new FastifyAdapter();\nadapter.getInstance().addHook('onRequest', (request, reply, done) => {\n  const target = request.raw.url ?? '';\n  // \"*\" is the legitimate request target of \"OPTIONS * HTTP/1.1\"\n  if (target[0] !== '/' && target !== '*') {\n    reply.code(400).send();\n    return;\n  }\n  done();\n});\n```\n\nRejecting or normalizing absolute-form targets at a reverse proxy in front of the application is equally effective.\n\n### Credit\n\nReported by ZeroVuln Labs.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"npm","product":"@nestjs/platform-fastify","affectedVersions":["pkg:npm/%40nestjs/platform-fastify < 11.2.4","pkg:npm/%40nestjs/platform-fastify >= 12.0.0, < 12.0.2"],"cwes":["CWE-288","CWE-436"],"tags":["osv","osv:ghsa-9c5c-9qcx-q35q","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-9c5c-9qcx-q35q","type":"advisory","title":"OSV GHSA-9c5c-9qcx-q35q"},{"url":"https://github.com/fastify/middie/security/advisories/GHSA-hx87-8wv7-pjv8","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest/security/advisories/GHSA-9c5c-9qcx-q35q","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest/pull/17737","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest/commit/5226fe084cf64b357de436f154bc89f2d319b621","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest/commit/dda252090ecb65009d9ff366444303796fc44fd7","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest","type":"vendor","title":"OSV package"},{"url":"https://github.com/nestjs/nest/releases/tag/v11.2.4","type":"other","title":"OSV web"},{"url":"https://github.com/nestjs/nest/releases/tag/v12.0.2","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T14:41:39.000Z","addedAt":"2026-09-30T19:54:24.807Z","updatedAt":"2026-09-30T19:54:24.807Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-9c5c-9qcx-q35q"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-9c5c-9qcx-q35q"}]},{"id":"0637a295-433e-40b3-b2af-37c225381e91","slug":"cve-2026-88828","externalId":"CVE-2026-88828","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-88828 — The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowin…","description":"The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.","cveId":"CVE-2026-88828","cvssScore":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://wpscan.com/vulnerability/52804421-8988-4d8a-9143-04683d05873d/","type":"advisory","title":"contact@wpscan.com"}],"epssScore":0.00167,"epssPercentile":0.05475,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T07:17:21.063Z","addedAt":"2026-09-28T07:50:40.046Z","updatedAt":"2026-09-28T17:50:41.028Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88828","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-88828","note":"authoritative record"}]},{"id":"ab142efb-ff86-4b8d-9140-e7ad62105e19","slug":"cve-2026-63493","externalId":"CVE-2026-63493","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-63493 — Snipe-IT is an IT asset/license management system.","description":"Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0.","cveId":"CVE-2026-63493","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"snipeitapp","product":"snipe-it","affectedVersions":["< 8.7.0"],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/grokability/snipe-it/commit/87c362962a670f427be071850b218e43eff5d08e","https://github.com/grokability/snipe-it/commit/c4ea7db51ca80bf11b1d04fbe46e4a64f54dc780","https://github.com/grokability/snipe-it/pull/19294","https://github.com/grokability/snipe-it/security/advisories/GHSA-hxcx-9h4f-42xx"],"references":[{"url":"https://github.com/grokability/snipe-it/commit/87c362962a670f427be071850b218e43eff5d08e","type":"patch","title":"Patch"},{"url":"https://github.com/grokability/snipe-it/commit/c4ea7db51ca80bf11b1d04fbe46e4a64f54dc780","type":"patch","title":"Patch"},{"url":"https://github.com/grokability/snipe-it/pull/19294","type":"patch","title":"Patch"},{"url":"https://github.com/grokability/snipe-it/releases/tag/v8.7.0","type":"advisory","title":"Release Notes"},{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-hxcx-9h4f-42xx","type":"patch","title":"Exploit"}],"epssScore":0.00268,"epssPercentile":0.17358,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T17:17:05.367Z","addedAt":"2026-09-24T17:50:40.099Z","updatedAt":"2026-09-29T19:50:40.598Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63493","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-63493","note":"authoritative record"}]},{"id":"b647d4d9-7a36-4713-9fb7-9a58a570ed23","slug":"cve-2026-90481","externalId":"CVE-2026-90481","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90481 — In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or …","description":"In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.","cveId":"CVE-2026-90481","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://portswigger.net/burp/releases/dast-2026-8","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.0033,"epssPercentile":0.24026,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T15:17:51.760Z","addedAt":"2026-09-24T15:50:40.349Z","updatedAt":"2026-09-24T21:50:44.314Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90481","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90481","note":"authoritative record"}]},{"id":"9a348790-6b75-47f1-9a57-11ea43c1dbd6","slug":"cve-2026-79680","externalId":"CVE-2026-79680","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79680 — Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module.","description":"Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.","cveId":"CVE-2026-79680","cvssScore":4.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:L/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://codereview.qt-project.org/c/qt/tqtc-qtvncserver/+/759160","type":"advisory","title":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"},{"url":"https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-79680:","type":"advisory","title":"a59d8014-47c4-4630-ab43-e1b13cbe58e3"}],"epssScore":0.00342,"epssPercentile":0.2568,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T11:16:47.117Z","addedAt":"2026-09-24T11:50:37.244Z","updatedAt":"2026-09-24T21:50:44.185Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79680","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79680","note":"authoritative record"}]},{"id":"f9bfc7da-975a-41b9-9ca2-394626be904c","slug":"cve-2026-93928","externalId":"CVE-2026-93928","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-93928 — Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc.","description":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass.\n\nThis issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.","cveId":"CVE-2026-93928","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/ecab-taxi-booking-manager/vulnerability/wordpress-taxi-booking-manager-for-woocommerce-plugin-2-0-8-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00401,"epssPercentile":0.32226,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-22T09:17:05.940Z","addedAt":"2026-09-22T09:50:37.351Z","updatedAt":"2026-09-22T19:50:41.049Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93928","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-93928","note":"authoritative record"}]},{"id":"4a6c1c4a-2ece-44f3-bdb2-facfd6feb8fe","slug":"cve-2026-58269","externalId":"CVE-2026-58269","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58269 — Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing.","description":"Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue.","cveId":"CVE-2026-58269","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"high","vendor":"npm","product":"@sync-in/server","affectedVersions":["pkg:npm/%40sync-in/server < 2.4.0"],"cwes":["CWE-288"],"tags":["nvd","status:received","osv","osv:ghsa-92cr-jxw4-5wjg","ecosystem:npm","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/Sync-in/server/security/advisories/GHSA-92cr-jxw4-5wjg","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-92cr-jxw4-5wjg","type":"advisory","title":"OSV GHSA-92cr-jxw4-5wjg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58269","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/Sync-in/server/pull/228","type":"other","title":"OSV web"},{"url":"https://github.com/Sync-in/server/commit/3ec74e2ea1f538fe1a3ac9487bdf24a19e548361","type":"other","title":"OSV web"},{"url":"https://github.com/Sync-in/server","type":"vendor","title":"OSV package"},{"url":"https://github.com/Sync-in/server/releases/tag/v2.4.0","type":"other","title":"OSV web"}],"epssScore":0.00225,"epssPercentile":0.12145,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-21T20:17:26.837Z","addedAt":"2026-09-21T21:50:38.208Z","updatedAt":"2026-09-24T23:50:42.093Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58269","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58269","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-92CR-JXW4-5WJG"}]},{"id":"6ce0783a-927f-484e-a31e-8293d85a59a7","slug":"cve-2026-81868","externalId":"CVE-2026-81868","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81868 — Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications.","description":"Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate supplied in the X-Client-Cert request header without proving possession of the corresponding private key. Common Cloud Foundry routers do not remove this header from inbound requests. When inbound requests are not restricted to a known trusted proxy source IP, an attacker who obtains the public certificate of an application instance in the target organization or space and can reach the application can spoof X-Client-Cert to bypass the SameOrg and SameSpace policies for the certificate validity period. This issue is fixed in version 4.3.0.","cveId":"CVE-2026-81868","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288","CWE-295"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/SteeltoeOSS/Steeltoe/commit/b626ef3d60aaf19c68eeeed5ee81045406c8c6d0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SteeltoeOSS/Steeltoe/releases/tag/4.3.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-5mq7-rwhj-4fh9","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0025,"epssPercentile":0.14999,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T16:17:47.607Z","addedAt":"2026-09-17T17:50:44.342Z","updatedAt":"2026-09-30T17:50:44.521Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81868","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81868","note":"authoritative record"}]},{"id":"8865cdfd-43c8-48d2-b093-8c13fcd235d2","slug":"cve-2026-62101","externalId":"CVE-2026-62101","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62101 — Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.","description":"Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.","cveId":"CVE-2026-62101","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/eduadmin-booking/vulnerability/wordpress-eduadmin-booking-plugin-5-4-2-broken-authentication-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":0.00606,"epssPercentile":0.47361,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T14:17:14.977Z","addedAt":"2026-09-17T15:50:38.690Z","updatedAt":"2026-09-17T21:50:37.268Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62101","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62101","note":"authoritative record"}]},{"id":"06dc0f87-bff8-4b61-8f1b-03f4c02bdf4a","slug":"cve-2026-14917","externalId":"CVE-2026-14917","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14917 — A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false.","description":"A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate the user without verifying a valid cryptographic signature.\n\n\n\nAs a result, an unauthenticated remote attacker may be able to submit a crafted SAML response and impersonate arbitrary users, including administrators","cveId":"CVE-2026-14917","cvssScore":7.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://developer.konghq.com/gateway/changelog/#3-15-0-3","type":"advisory","title":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb"}],"epssScore":0.00694,"epssPercentile":0.51469,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T10:16:48.373Z","addedAt":"2026-09-16T11:50:38.359Z","updatedAt":"2026-09-18T19:50:38.152Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14917","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14917","note":"authoritative record"}]},{"id":"ba5a5ee9-320a-4119-9d1a-d7de66d97874","slug":"cve-2026-27546","externalId":"CVE-2026-27546","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-27546 — An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are …","description":"An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.","cveId":"CVE-2026-27546","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-288"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.certvde.com/en/advisories/VDE-2026-014/","type":"advisory","title":"info@cert.vde.com"},{"url":"https://www.certvde.com/en/advisories/VDE-2026-027/","type":"advisory","title":"info@cert.vde.com"},{"url":"https://www.certvde.com/en/advisories/VDE-2026-028/","type":"advisory","title":"info@cert.vde.com"}],"epssScore":0.01017,"epssPercentile":0.6223,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T08:16:36.850Z","addedAt":"2026-09-16T09:50:35.623Z","updatedAt":"2026-09-16T19:50:45.944Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27546","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-27546","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":169,"totalPages":9,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:47:04.502Z","durationMs":23,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-288"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}