{"success":true,"data":{"threats":[{"id":"3bc71483-7c2f-464f-82c9-bfb79d61bb5b","slug":"cve-2026-84891","externalId":"CVE-2026-84891","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84891 — IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.","description":"IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.","cveId":"CVE-2026-84891","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7291675","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:34.573Z","addedAt":"2026-10-08T23:06:40.666Z","updatedAt":"2026-10-08T23:06:40.666Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84891","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84891","note":"authoritative record"}]},{"id":"3e4bcc36-08ac-4e7e-8fdd-a07fae3a7636","slug":"cve-2026-84250","externalId":"CVE-2026-84250","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84250 — IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component.","description":"IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.","cveId":"CVE-2026-84250","cvssScore":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.460Z","addedAt":"2026-10-08T21:05:53.540Z","updatedAt":"2026-10-08T21:05:53.540Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84250","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84250","note":"authoritative record"}]},{"id":"8bcdae32-87f9-4709-b879-72a37ae0702d","slug":"cve-2026-85488","externalId":"CVE-2026-85488","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85488 — Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer.","description":"Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place.","cveId":"CVE-2026-85488","cvssScore":7,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/38384","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00091,"epssPercentile":0.00467,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T07:16:32.590Z","addedAt":"2026-10-08T08:39:29.320Z","updatedAt":"2026-10-08T21:05:47.580Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85488","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85488","note":"authoritative record"}]},{"id":"55491c5a-bc36-49ec-8572-697c91e868bc","slug":"cve-2026-85422","externalId":"CVE-2026-85422","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85422 — A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binar…","description":"A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.","cveId":"CVE-2026-85422","cvssScore":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/38379","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00106,"epssPercentile":0.01025,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T07:16:32.033Z","addedAt":"2026-10-08T08:39:29.289Z","updatedAt":"2026-10-08T21:05:47.479Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85422","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85422","note":"authoritative record"}]},{"id":"f9ff9f2b-19da-4a39-a5fd-66dde849792d","slug":"cve-2026-92861","externalId":"CVE-2026-92861","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-92861 — The Android application \"Ticket Ryutsu Center\" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the applic…","description":"The Android application \"Ticket Ryutsu Center\" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.","cveId":"CVE-2026-92861","cvssScore":5.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jvn.jp/en/jp/JVN53292492/","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://play.google.com/store/apps/details?id=jp.co.ticket","type":"advisory","title":"vultures@jpcert.or.jp"}],"epssScore":0.0011,"epssPercentile":0.01177,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:37.530Z","addedAt":"2026-10-08T04:39:32.967Z","updatedAt":"2026-10-08T23:06:37.063Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92861","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-92861","note":"authoritative record"}]},{"id":"d47d7643-2eb4-4f44-848b-0c27a1b2a4ab","slug":"cve-2026-62252","externalId":"CVE-2026-62252","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62252 — Homer is open source telecom observability software.","description":"Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.","cveId":"CVE-2026-62252","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"Go","product":"github.com/sipcapture/homer-app","affectedVersions":["pkg:golang/github.com/sipcapture/homer-app < 0.0.0-20260625091610-b2e942031ff8"],"cwes":["CWE-798"],"tags":["nvd","status:received","osv","osv:ghsa-6xp5-7rcx-xfgx","ecosystem:go","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/pull/838","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/releases/tag/11.0.283","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/GHSA-6xp5-7rcx-xfgx","type":"advisory","title":"OSV GHSA-6xp5-7rcx-xfgx"},{"url":"https://github.com/sipcapture/homer","type":"vendor","title":"OSV package"}],"epssScore":0.00653,"epssPercentile":0.49702,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T17:16:56.467Z","addedAt":"2026-10-07T18:39:31.344Z","updatedAt":"2026-10-08T23:06:36.733Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62252","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62252","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-6XP5-7RCX-XFGX"}]},{"id":"68a9f3c9-616d-40a6-83c0-aa808610c795","slug":"cve-2026-102161","externalId":"CVE-2026-102161","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102161 — An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards clie…","description":"An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.","cveId":"CVE-2026-102161","cvssScore":8.7,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-290","CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24806-security-advisory-0190","type":"advisory","title":"psirt@arista.com"}],"epssScore":0.00216,"epssPercentile":0.11017,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:11.230Z","addedAt":"2026-10-06T20:39:32.736Z","updatedAt":"2026-10-07T14:39:33.889Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102161","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102161","note":"authoritative record"}]},{"id":"54e365b8-84d1-40e6-8c8a-e7c60c4cb5c0","slug":"cve-2026-61421","externalId":"CVE-2026-61421","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-61421 — Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization.","description":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","cveId":"CVE-2026-61421","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":"dell","product":"container storage modules","affectedVersions":["< 1.18.0"],"cwes":["CWE-798"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00344,"epssPercentile":0.25849,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:17:18.767Z","addedAt":"2026-10-06T15:51:00.486Z","updatedAt":"2026-10-08T14:40:01.491Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61421","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61421","note":"authoritative record"}]},{"id":"4d356f7b-3357-47a8-b001-82a8b0aaf1af","slug":"cve-2026-54472","externalId":"CVE-2026-54472","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-54472 — Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs.","description":"Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8","cveId":"CVE-2026-54472","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":"dell","product":"container storage modules","affectedVersions":["< 1.18.0"],"cwes":["CWE-798"],"tags":["nvd","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00544,"epssPercentile":0.43897,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T15:17:18.483Z","addedAt":"2026-10-06T15:51:00.481Z","updatedAt":"2026-10-08T14:40:01.479Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54472","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-54472","note":"authoritative record"}]},{"id":"d5f731d6-5480-48c7-a2d3-8ef2062c7f9a","slug":"cve-2026-105641","externalId":"CVE-2026-105641","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105641 — Plane is an open-source project management tool.","description":"Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.","cveId":"CVE-2026-105641","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/pull/9291","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/releases/tag/v1.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.0046,"epssPercentile":0.37911,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:18.560Z","addedAt":"2026-10-05T19:50:42.805Z","updatedAt":"2026-10-07T22:39:35.998Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105641","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105641","note":"authoritative record"}]},{"id":"1779ee9f-81ce-4117-993e-bc3b668a5871","slug":"cve-2026-105147","externalId":"CVE-2026-105147","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105147 — A vulnerability was determined in SciPhi-AI R2R up to 3.6.6.","description":"A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","cveId":"CVE-2026-105147","cvssScore":5.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-259","CWE-798"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gist.github.com/DReazer/6bc4f88053ec35f8358395bcc0d1a0bb","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105147","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/947748","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413372","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413372/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00278,"epssPercentile":0.18579,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T13:16:54.773Z","addedAt":"2026-10-04T13:50:39.871Z","updatedAt":"2026-10-05T17:50:42.571Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105147","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105147","note":"authoritative record"}]},{"id":"65f8c3d7-4fc2-4c50-8607-2d403b1a7e6a","slug":"cve-2026-105141","externalId":"CVE-2026-105141","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105141 — A security flaw has been discovered in topoteretes cognee up to 1.5.4.","description":"A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET results in hard-coded credentials. The attack may be launched remotely. Upgrading to version 1.6.0 is sufficient to fix this issue. The patch is identified as fa65fc0cd86cdba48d19aa76e36be862be982f5d. Upgrading the affected component is advised.","cveId":"CVE-2026-105141","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-259","CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/topoteretes/cognee/","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/commit/fa65fc0cd86cdba48d19aa76e36be862be982f5d","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/pull/5062","type":"advisory","title":"cna@vuldb.com"},{"url":"https://github.com/topoteretes/cognee/releases/tag/v1.6.0","type":"advisory","title":"cna@vuldb.com"},{"url":"https://linear.app/cognee/issue/SDK-720/replace-the-super-secret-fallback-for-token-signing-secrets-with-a-per","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105141","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/944531","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413365","type":"advisory","title":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413365/cti","type":"advisory","title":"cna@vuldb.com"}],"epssScore":0.00337,"epssPercentile":0.25077,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-04T09:16:39.203Z","addedAt":"2026-10-04T09:50:39.879Z","updatedAt":"2026-10-06T15:50:56.617Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105141","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105141","note":"authoritative record"}]},{"id":"6bf4e0fb-0b96-4838-bc53-004e8ee53698","slug":"ghsa-gg6r-gp4c-89hp","externalId":"GHSA-gg6r-gp4c-89hp","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Trigger.dev: V1 coordinator default-secret unauth Socket.IO","description":"## TL;DR\n\nThe /coordinator Socket.IO namespace mounts on every webapp boot and authenticates with a default secret (\"coordinator-secret\") baked into source. The override variable isn't documented in the self-host docs, .env.example, or helm values, so any operator who didn't read source ships with the default. Once connected, READY_FOR_EXECUTION returns the run's decrypted env vars. Anyone who can reach a default-config self-hosted webapp can pull production secrets out of any run whose internal id they can find.\n\n## Vulnerabilities\n\nThis attack is made possible by 3 vulnerabilities in Trigger.dev:\n\n### 1. Hardcoded default authentication secret (CWE-798, Critical)\nPROVIDER_SECRET and COORDINATOR_SECRET are declared with `.default(\"provider-secret\")` / `.default(\"coordinator-secret\")` in [`apps/webapp/app/env.server.ts:289-290`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/env.server.ts#L289-L290). The values are present in the public source repo, neither var is documented in `docs/self-hosting/env/*.mdx`, `hosting/docker/.env.example`, or `hosting/k8s/helm/values.yaml`, and the auth check at [`packages/core/src/v3/zodNamespace.ts:148`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/packages/core/src/v3/zodNamespace.ts#L148) is a plain string compare against that published value\n\n### 2. Coordinator handler returns decrypted env vars to any authenticated caller (CWE-200, High)\n`READY_FOR_EXECUTION` at [`apps/webapp/app/v3/handleSocketIo.server.ts:123`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/v3/handleSocketIo.server.ts#L123) calls `sharedQueueTasks.getLatestExecutionPayloadFromRun(runId, ...)`, which at [`apps/webapp/app/v3/marqs/sharedQueueConsumer.server.ts:1881-1895`](https://github.com/triggerdotdev/trigger.dev/blob/v4.4.4/apps/webapp/app/v3/marqs/sharedQueueConsumer.server.ts#L1881-L1895) returns `payload.environment` as the run's decrypted env-var dictionary. Any internal runId is enough to exfil that run's full env, regardless of tenant. Note: this read handler lives in V1-only `marqs/` code, so it returns nothing for runs on V2 (Run Engine 2.0). Self-hosts still on V1 are fully exposed; v4-only deployments only see the write handlers below\n\n### 3. Other coordinator handlers accept attacker-controlled writes against arbitrary runs (CWE-862, High)\nTASK_RUN_COMPLETED, TASK_RUN_COMPLETED_WITH_ACK, TASK_RUN_FAILED_TO_RUN, CHECKPOINT_CREATED, CREATE_WORKER and friends invoke webapp services with attacker-supplied completion / attempt / worker payloads. None of them check that the caller has authority over the runId or attemptId in the message. `attempt_*` friendlyIds leak through every dashboard URL and emailed alert, so writes are trivially reachable without any internal id\n\n## Exploit chain / PoC\n\n```js\nimport { io } from \"socket.io-client\";\n\nconst sock = io(\"https://<self-hosted-target>/coordinator\", {\n  auth: { token: \"coordinator-secret\" },\n  transports: [\"websocket\"],\n});\n\nsock.on(\"connect\", () => {\n  // exfil decrypted env for a known run id\n  sock.emit(\"READY_FOR_EXECUTION\", { runId: \"<runId>\", totalCompletions: 0 }, (res) => {\n    console.log(res.payload.environment);\n    // { DATABASE_URL: \"...\", STRIPE_SECRET_KEY: \"...\", OPENAI_API_KEY: \"...\", ... }\n  });\n\n  // mark any attempt failed\n  sock.emit(\"TASK_RUN_FAILED_TO_RUN\", {\n    completion: {\n      id: \"<attempt_friendlyId>\",\n      ok: false,\n      error: { type: \"INTERNAL_ERROR\", code: \"FORGED\", message: \"owned\" },\n    },\n  });\n});\n```\n\n## Resolution\n\nFixed in **v4.5.4**. The entire end-of-life V1 (Run Engine 1.0) execution stack was removed in commit `5ba8557a5` (#4236) — including the `/coordinator`, `/provider`, and `/shared-queue` Socket.IO namespaces, `packages/core/src/v3/zodNamespace.ts`, the `marqs` shared-queue consumer, and the `PROVIDER_SECRET` / `COORDINATOR_SECRET` environment variables.\n\nAll three vulnerabilities are absent in v4.5.4 and later: the vulnerable namespaces no longer mount, the `READY_FOR_EXECUTION` env-var read handler and the unauthenticated write handlers no longer exist, and the hardcoded default secrets are gone.\n\n**Affected:** self-hosted Trigger.dev `< 4.5.4`. Vulnerability #2 (decrypted env-var exfiltration) additionally required a deployment still running Run Engine 1.0; v4-only (Run Engine 2.0) deployments were exposed only to the write handlers (#3).\n\n**Managed cloud (cloud.trigger.dev) was not affected:** it was configured with non-default control-plane secrets, so the default-secret entry point (vulnerability #1) that gates the chain never applied.\n\n**Action:** self-hosted operators on any release before v4.5.4 should upgrade to v4.5.4 or later.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","severity":"critical","vendor":"npm","product":"trigger.dev","affectedVersions":["pkg:npm/trigger.dev < 4.5.4"],"cwes":["CWE-200","CWE-798","CWE-862"],"tags":["osv","osv:ghsa-gg6r-gp4c-89hp","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-gg6r-gp4c-89hp","type":"advisory","title":"OSV GHSA-gg6r-gp4c-89hp"},{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-gg6r-gp4c-89hp","type":"other","title":"OSV web"},{"url":"https://github.com/triggerdotdev/trigger.dev/pull/4236","type":"other","title":"OSV web"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/5ba8557a51533be05f04245b03e1ca975cd57eff","type":"other","title":"OSV web"},{"url":"https://github.com/triggerdotdev/trigger.dev","type":"vendor","title":"OSV package"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.4","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T22:39:00.000Z","addedAt":"2026-10-03T01:54:23.610Z","updatedAt":"2026-10-03T01:54:23.610Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-gg6r-gp4c-89hp"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-gg6r-gp4c-89hp"}]},{"id":"55c96f7b-c78a-4668-801f-7e97f1e0ccfe","slug":"cve-2026-94592","externalId":"CVE-2026-94592","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94592 — Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather …","description":"Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.","cveId":"CVE-2026-94592","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json","type":"advisory","title":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01","type":"advisory","title":"ics-cert@hq.dhs.gov"}],"epssScore":0.00127,"epssPercentile":0.02048,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T22:16:56.187Z","addedAt":"2026-10-02T23:50:39.692Z","updatedAt":"2026-10-06T15:50:55.817Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94592","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94592","note":"authoritative record"}]},{"id":"4b187550-3452-4302-8980-18f758bfefcb","slug":"cve-2026-103097","externalId":"CVE-2026-103097","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103097 — An API key is\nhardcoded and retrievable from the application package.","description":"An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.","cveId":"CVE-2026-103097","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-312","CWE-540","CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","type":"advisory","title":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"epssScore":0.00152,"epssPercentile":0.03807,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T01:16:43.070Z","addedAt":"2026-10-02T01:50:41.230Z","updatedAt":"2026-10-02T21:50:40.135Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103097","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103097","note":"authoritative record"}]},{"id":"9f4f206a-004d-4973-8024-d53e1fd409ef","slug":"cve-2026-103096","externalId":"CVE-2026-103096","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103096 — API\nkey is hardcoded and retrievable from the application package.","description":"API\nkey is hardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.","cveId":"CVE-2026-103096","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-312","CWE-540","CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","type":"advisory","title":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"epssScore":0.00152,"epssPercentile":0.03807,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T01:16:42.930Z","addedAt":"2026-10-02T01:50:41.225Z","updatedAt":"2026-10-02T21:50:40.129Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103096","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103096","note":"authoritative record"}]},{"id":"8d754823-fde9-4097-b921-f41649ac6393","slug":"cve-2026-27873","externalId":"CVE-2026-27873","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-27873 — - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.","description":"- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.\n\nThis issue affects EasyIO FG: before 2.0b52.","cveId":"CVE-2026-27873","cvssScore":5.6,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories","type":"advisory","title":"productsecurity@jci.com"}],"epssScore":0.00087,"epssPercentile":0.00335,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:01.450Z","addedAt":"2026-10-01T23:50:39.524Z","updatedAt":"2026-10-02T19:50:40.455Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27873","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-27873","note":"authoritative record"}]},{"id":"9a245d48-7759-44d1-ae49-2c829ef43350","slug":"cve-2026-55395","externalId":"CVE-2026-55395","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55395 — Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenti…","description":"Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.","cveId":"CVE-2026-55395","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0031.md","type":"advisory","title":"mandiant-cve@google.com"}],"epssScore":0.00185,"epssPercentile":0.07381,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T21:17:21.830Z","addedAt":"2026-10-01T21:50:40.864Z","updatedAt":"2026-10-02T15:50:40.351Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55395","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55395","note":"authoritative record"}]},{"id":"f2998946-16e2-4288-a14b-0af91fb43bf3","slug":"cve-2026-27874","externalId":"CVE-2026-27874","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-27874 — : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.","description":": Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials.\n\nThis issue affects EasyIO FS32: before 3.0b63.","cveId":"CVE-2026-27874","cvssScore":5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories","type":"advisory","title":"productsecurity@jci.com"}],"epssScore":0.00135,"epssPercentile":0.02528,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T21:17:20.227Z","addedAt":"2026-10-01T21:50:40.847Z","updatedAt":"2026-10-02T19:50:40.408Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27874","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-27874","note":"authoritative record"}]},{"id":"0dd626b4-5200-4d5b-9b9d-1b8257ad75a4","slug":"cve-2026-102666","externalId":"CVE-2026-102666","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102666 — The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and s…","description":"The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.","cveId":"CVE-2026-102666","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-798"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/VA-26-275-03.json","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-102666","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"}],"epssScore":0.00166,"epssPercentile":0.05287,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T20:17:21.610Z","addedAt":"2026-10-01T21:50:40.662Z","updatedAt":"2026-10-07T16:39:30.275Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102666","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102666","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":200,"totalPages":10,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:15:36.373Z","durationMs":20,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-798"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}