{"success":true,"data":{"threats":[{"id":"7ac00845-383f-4437-bd85-0866f0e48f9f","slug":"cve-2026-105331","externalId":"CVE-2026-105331","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105331 — Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plu…","description":"Local privilege escalation in Checkmk 2.5.0 before 2.5.0p10 allows a user with access to edit the Oracle Instant Client referenced by the agent plugin 'mk-oracle' to escalate their privileges if an agent has this plugin enabled.","cveId":"CVE-2026-105331","cvssScore":5.2,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426","CWE-829"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://checkmk.com/werk/22619","type":"advisory","title":"security@checkmk.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:32.530Z","addedAt":"2026-10-08T16:39:35.584Z","updatedAt":"2026-10-08T16:39:35.584Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105331","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105331","note":"authoritative record"}]},{"id":"094b4241-30e3-4340-a8d6-92e6b1b8d11b","slug":"cve-2026-106505","externalId":"CVE-2026-106505","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106505 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.","cveId":"CVE-2026-106505","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L","severity":"high","vendor":"npm","product":"@backstage/plugin-techdocs-node","affectedVersions":["pkg:npm/%40backstage/plugin-techdocs-node < 1.15.4"],"cwes":["CWE-426","CWE-436"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-p75x-jh7p-ppcx","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/a7d995f11a5d27f0efbdbe8bb6c21b06988c79c9","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/ef92d3d2b76046205c580e7152956514c15640db","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-p75x-jh7p-ppcx","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-p75x-jh7p-ppcx","type":"advisory","title":"OSV GHSA-p75x-jh7p-ppcx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106505","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00274,"epssPercentile":0.18182,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:05.837Z","addedAt":"2026-10-06T22:39:33.234Z","updatedAt":"2026-10-07T18:42:44.455Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106505","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106505","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-P75X-JH7P-PPCX"}]},{"id":"421ecc28-84d1-42c9-95d5-11059c8bdf33","slug":"cve-2026-104809","externalId":"CVE-2026-104809","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104809 — DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the exp…","description":"DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.","cveId":"CVE-2026-104809","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Amber","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-73","CWE-426","CWE-427","CWE-494","CWE-829"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna","type":"advisory","title":"vulnerability@ncsc.ch"}],"epssScore":0.00087,"epssPercentile":0.00329,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T09:17:10.007Z","addedAt":"2026-10-05T09:50:40.896Z","updatedAt":"2026-10-06T15:50:57.446Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104809","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104809","note":"authoritative record"}]},{"id":"da2b1f5d-a7fa-4a6f-b7b3-95af35db3ade","slug":"cve-2026-59265","externalId":"CVE-2026-59265","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-59265 — A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing ar…","description":"A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user.\n\n\n\nThis issue is expected to be fixed in version 4.1.17, which is in the release candidate phase.\n\n\n\nUntil then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.","cveId":"CVE-2026-59265","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/apache/openoffice/commit/95923fd437e06edd38a4f0e139a27c755a6f3ba6.patch","type":"advisory","title":"security@apache.org"},{"url":"https://github.com/apache/openoffice/commit/c699bed3f75e79bd64ddec9dec49f9e210eed281.patch","type":"advisory","title":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/svfdc1jtpqlw7mo6lgg9fthcmf754pl5","type":"advisory","title":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/02/2","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/08/7","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00429,"epssPercentile":0.35093,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:17:03.917Z","addedAt":"2026-10-02T19:50:41.873Z","updatedAt":"2026-10-08T04:39:32.130Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59265","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-59265","note":"authoritative record"}]},{"id":"804156d6-9b3b-423c-adde-285f408c9dff","slug":"cve-2026-19547","externalId":"CVE-2026-19547","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19547 — Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking.","description":"Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\\\gs\\\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any authenticated user to create directories at the root of C:\\\\, an attacker who is an authenticated local user can create the expected directory structure and plant a malicious PostScript file. When any user or service subsequently runs Ghostscript, the planted file is automatically loaded and executed with the full privileges of the Ghostscript process. This results in full compromise of Ghostscript process context, as well as running arbitrary code on the machine with Ghostscript process privileges.\n\n\nThis issue was fixed in version 10.08.0.","cveId":"CVE-2026-19547","cvssScore":7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugs.ghostscript.com/show_bug.cgi?id=709522","type":"advisory","title":"cvd@cert.pl"},{"url":"https://cert.pl/en/posts/2026/09/CVE-2026-19547","type":"advisory","title":"cvd@cert.pl"},{"url":"https://ghostscript.com/","type":"advisory","title":"cvd@cert.pl"}],"epssScore":0.00159,"epssPercentile":0.04465,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T10:17:11.410Z","addedAt":"2026-09-29T11:50:40.373Z","updatedAt":"2026-09-30T19:50:42.406Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19547","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19547","note":"authoritative record"}]},{"id":"b0817203-8b8f-4ad1-b431-07f32b2bd970","slug":"cve-2026-87723","externalId":"CVE-2026-87723","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-87723 — In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlle…","description":"In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.","cveId":"CVE-2026-87723","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/google/fuse-archive/commit/4b13a49b4bf66e0960241bab78987dde268a8b81","type":"advisory","title":"cve-coordination@google.com"},{"url":"https://github.com/google/fuse-archive/commit/6f086e6381428d5b818dcb1bf7b9204e6bf017f0","type":"advisory","title":"cve-coordination@google.com"}],"epssScore":0.00113,"epssPercentile":0.01328,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-28T05:16:30.840Z","addedAt":"2026-09-28T05:50:38.025Z","updatedAt":"2026-09-29T21:50:40.495Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87723","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-87723","note":"authoritative record"}]},{"id":"93ef8aa4-9d55-414f-bd5b-b07e6548e721","slug":"cve-2026-100584","externalId":"CVE-2026-100584","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100584 — OpenClaw is an npm-distributed agent runtime.","description":"OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory. If lower-trust content can place an executable with an approved basename into an agent-writable workspace and steer an approved PowerShell command that uses a bare executable name, OpenClaw may run the workspace file instead of the allowlisted path, executing arbitrary code with the privileges of the Gateway or node-host user. The issue does not require replacement of the approved executable itself. Version 2026.7.1 contains a fix; as a workaround, avoid bare executable names in approved PowerShell commands and keep executable files out of agent-writable workspaces.","cveId":"CVE-2026-100584","cvssScore":5.4,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-rgjw-6v73-php6","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-before-2026.7.1-allowlist-bypass-via-workspace-shadows","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00097,"epssPercentile":0.0071,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-26T03:17:06.373Z","addedAt":"2026-09-26T03:50:37.793Z","updatedAt":"2026-10-05T15:50:46.257Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100584","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100584","note":"authoritative record"}]},{"id":"61a5ae4d-7a63-42a8-8a68-9dcb543733e0","slug":"cve-2026-100310","externalId":"CVE-2026-100310","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-100310 — GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper p…","description":"GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.","cveId":"CVE-2026-100310","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://ftp.gnu.org/gnu/libextractor/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://git.gnunet.org/gnunet/libextractor/commit/6edfa653c048800e24a17f7e8cc2bb42659b8d01.html","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/Haitam-lazaar/libextractor-privesc","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.gnu.org/software/libextractor/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gnu-libextractor-before-1.16-privilege-escalation-via-libextractor-prefix","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/25/25","type":"advisory","title":"af854a3a-2127-422b-91ae-364da2661108"}],"epssScore":0.00136,"epssPercentile":0.02631,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T20:17:05.833Z","addedAt":"2026-09-25T21:50:38.139Z","updatedAt":"2026-09-30T17:50:45.108Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-100310","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-100310","note":"authoritative record"}]},{"id":"c5cd8828-f728-4661-95b7-e1267cddfe6f","slug":"cve-2026-68492","externalId":"CVE-2026-68492","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-68492 — An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to exe…","description":"An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the \"Plesk RESTful API\" extension from 2.4.2 before 2.4.7.","cveId":"CVE-2026-68492","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.plesk.com/hc/en-us/articles/43644058632983","type":"advisory","title":"support@hackerone.com"}],"epssScore":0.00384,"epssPercentile":0.30307,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-23T20:17:13.583Z","addedAt":"2026-09-23T21:50:38.593Z","updatedAt":"2026-09-24T21:50:44.010Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68492","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-68492","note":"authoritative record"}]},{"id":"4f522e7c-4492-4cfb-842e-847958dd0ab0","slug":"cve-2026-92587","externalId":"CVE-2026-92587","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92587 — n8n is a workflow automation platform.","description":"n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical URL string pass the file-access check while git resolved it outside the sandbox. A subsequent fetch or pull read a git repository outside N8N_RESTRICT_FILE_ACCESS_TO and merged its objects into the user's own repository, where their contents could be read back. The issue is fixed in n8n 1.123.76, 2.37.7, and 2.38.2, which resolve the remote reference from the directory git actually operates in before applying the sandbox check. As a workaround, the Git node can be disabled by adding n8n-nodes-base.git to NODES_EXCLUDE.","cveId":"CVE-2026-92587","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-fm93-2x43-6676","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-1.123.76-sandbox-escape-via-git-relative-url","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00306,"epssPercentile":0.21473,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T22:18:29.293Z","addedAt":"2026-09-16T23:50:35.616Z","updatedAt":"2026-09-22T21:50:39.707Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92587","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92587","note":"authoritative record"}]},{"id":"6f442f79-2532-4677-a653-1991ff21b66f","slug":"cve-2026-0307","externalId":"CVE-2026-0307","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-0307 — Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges t…","description":"Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.\n\n\n\nThis GlobalProtect app on iOS, Android and ChromeOS is not impacted.","cveId":"CVE-2026-0307","cvssScore":5.9,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0307","type":"advisory","title":"psirt@paloaltonetworks.com"}],"epssScore":0.00105,"epssPercentile":0.00987,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T06:17:03.170Z","addedAt":"2026-09-10T07:50:33.414Z","updatedAt":"2026-09-11T05:50:34.525Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0307","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-0307","note":"authoritative record"}]},{"id":"5ec7e957-1258-4330-b47f-b96e9c70cb08","slug":"cve-2026-81192","externalId":"CVE-2026-81192","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81192 — `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vul…","description":"`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.","cveId":"CVE-2026-81192","cvssScore":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00177,"epssPercentile":0.0664,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T21:18:43.447Z","addedAt":"2026-09-08T21:50:42.477Z","updatedAt":"2026-09-10T21:50:35.167Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81192","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81192","note":"authoritative record"}]},{"id":"2583b90b-9d9a-4ec3-8c02-7acfe02e7667","slug":"cve-2026-80159","externalId":"CVE-2026-80159","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-80159 — Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation.","description":"Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.","cveId":"CVE-2026-80159","cvssScore":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":"adobe","product":"acrobat","affectedVersions":[">= 24.001.20604, < 24.001.30429",">= 15.008.20082, < 26.002.21901"],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00195,"epssPercentile":0.08356,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T21:18:42.980Z","addedAt":"2026-09-08T21:50:42.456Z","updatedAt":"2026-09-10T21:50:35.153Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80159","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-80159","note":"authoritative record"}]},{"id":"29d6f8fc-cc3b-4252-85ec-440612435c6b","slug":"cve-2026-78574","externalId":"CVE-2026-78574","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78574 — The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verifica…","description":"The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.","cveId":"CVE-2026-78574","cvssScore":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","severity":"medium","vendor":"okta","product":"hyperdrive","affectedVersions":[">= 1.2.0, <= 1.5.1"],"cwes":["CWE-426"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://trust.okta.com/security-advisories/improper-assembly-resolution-in-okta-hyperdrive-integration-plugin-registry-handling-cve-2026-78574","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00099,"epssPercentile":0.00753,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T20:18:36.417Z","addedAt":"2026-09-08T21:50:42.257Z","updatedAt":"2026-09-23T19:50:38.496Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78574","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78574","note":"authoritative record"}]},{"id":"bbd3bb82-b4c0-4b65-bff3-555b2490673b","slug":"cve-2026-69785","externalId":"CVE-2026-69785","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69785 — Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.","description":"Untrusted search path in Windows Smart Card allows an authorized attacker to elevate privileges locally.","cveId":"CVE-2026-69785","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","r2","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-426"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69785"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69785","type":"patch","title":"Patch"}],"epssScore":0.00457,"epssPercentile":0.37672,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:19:49.967Z","addedAt":"2026-09-08T19:50:41.142Z","updatedAt":"2026-09-24T23:50:40.399Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69785","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69785","note":"authoritative record"}]},{"id":"86fd0333-f1b8-4a6d-a7c6-ca9cf218058c","slug":"cve-2026-69328","externalId":"CVE-2026-69328","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-69328 — Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.","description":"Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.","cveId":"CVE-2026-69328","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"windows 10 1607","affectedVersions":["< 10.0.14393.9512","< 10.0.17763.9245","< 10.0.19044.7725","< 10.0.19045.7725","< 10.0.22631.7582","< 10.0.26100.9445","< 10.0.26200.9445","< 10.0.28000.2954","< 10.0.20348.5622","< 10.0.26100.33438"],"cwes":["CWE-426"],"tags":["nvd","status:awaiting-analysis","status:analyzed","msrc","vendor-advisory","microsoft","cve"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69328"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69328","type":"vendor","title":"Microsoft MSRC: CVE-2026-69328 Windows Storage Elevation of Privilege Vulnerability"}],"epssScore":0.00457,"epssPercentile":0.37672,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T18:18:50.447Z","addedAt":"2026-09-08T19:50:39.281Z","updatedAt":"2026-09-30T14:53:00.956Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69328","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-69328","note":"authoritative record"}]},{"id":"f08d01f9-666d-4fc2-bbb6-5b5fb9c0d7c9","slug":"cve-2026-84226","externalId":"CVE-2026-84226","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack d…","description":"OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps","cveId":"CVE-2026-84226","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://community.openvpn.net/Security%20Announcements/CVE-2026-84226","type":"advisory","title":"security@openvpn.net"}],"epssScore":0.00142,"epssPercentile":0.03013,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-07T08:17:13.653Z","addedAt":"2026-09-07T09:50:33.041Z","updatedAt":"2026-09-08T19:50:37.374Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84226","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84226","note":"authoritative record"}]},{"id":"3a1568cd-6694-41bd-885e-a3ccb127e4d9","slug":"cve-2026-82862","externalId":"CVE-2026-82862","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-82862 — Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper sc…","description":"Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.","cveId":"CVE-2026-82862","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-mjcg-x5mr-27ww","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hulumi-before-1.3.2-helper-script-shadowing-via-workspace-files","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00192,"epssPercentile":0.08148,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-31T09:17:06.643Z","addedAt":"2026-08-31T09:50:31.477Z","updatedAt":"2026-09-01T15:50:34.126Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82862","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-82862","note":"authoritative record"}]},{"id":"fed2d1fb-fa80-4520-8998-bde96825035b","slug":"cve-2026-81697","externalId":"CVE-2026-81697","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81697 — openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, whe…","description":"openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name 'crypt_settings.json'. As a result, the legacy Tk GUI's SettingsTab reads and writes KDF settings from crypt_settings.json in the process launch (current working) directory instead of the user's home directory. An attacker who plants a malicious crypt_settings.json (e.g. sha256:1 with all memory-hard KDFs disabled) can silently downgrade encryption performed in that GUI session to roughly one hash round, bypassing the weak-KDF preflight and enabling offline brute-force attacks against the resulting ciphertext. Fixed in 1.4.9.","cveId":"CVE-2026-81697","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-426"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-7j2v-g84w-m75v","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-kdf-downgrade-via-cwd-relative-configuration","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00206,"epssPercentile":0.09703,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T17:20:59.893Z","addedAt":"2026-08-27T17:50:36.006Z","updatedAt":"2026-09-23T17:50:38.162Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81697","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81697","note":"authoritative record"}]},{"id":"7da88730-9401-43aa-a534-fe60fa44ad65","slug":"cve-2026-75768","externalId":"CVE-2026-75768","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-75768 — Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the cur…","description":"Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.","cveId":"CVE-2026-75768","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"adobe","product":"substance 3d painter","affectedVersions":["< 12.1.3"],"cwes":["CWE-426"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://helpx.adobe.com/security/products/substance3d_painter/apsb26-129.html","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00293,"epssPercentile":0.20077,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T18:18:04.097Z","addedAt":"2026-08-25T19:50:31.952Z","updatedAt":"2026-08-31T19:50:33.299Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75768","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-75768","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":78,"totalPages":4,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:55:18.178Z","durationMs":25,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-426"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}