Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-49267

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] smtp_ssl`. An attacker positioned between the worker and the configured SMTP server (network MITM — typical hostile-network attack-surface for environments where the SMTP relay sits outside the worker's trust boundary) could present a self-signed certificate, have the w

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49261

A flaw was found in MariaDB server. When the `wsrep_notify_cmd` feature is enabled, a remote attacker could exploit this vulnerability by embedding shell commands in the name of a joiner node. This could lead to arbitrary code execution on the server, allowing the attacker to take full control of the affected system.

PUBLISHED
Vendor
Red Hat, MariaDB, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, server, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Hardened Images, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images
Provider severity
CRITICAL
Conflicts
3

CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` returns `'/usr/local/bin/weasyprint'` with the single-quote characters as part of the string, so `is_executable()` looks for a file whose actual na

PUBLISHED
Vendor
pontedilana
Product
php-weasyprint
Provider severity
HIGH
Conflicts
0

CVE-2026-4926

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, path-to-regexp, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 3, Red Hat Fuse 7, OpenShift Pipelines, Red Hat OpenShift AI (RHOAI), Red Hat JBoss Enterprise Application Platform 8, Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 3, Red Hat OpenShift AI (RHOAI), Red Hat Fuse 7, Red Hat Build of Podman Desktop, Red Hat OpenShift Virtualization 4, OpenShift Service Mesh 2, Red Hat Developer Hub 1.9, Red Hat Satellite 6, Red Hat Fuse 7, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Red Hat Developer Hub, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Cryostat 4, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift GitOps, Logging Subsystem for Red Hat OpenShift, OpenShift Service Mesh 2, OpenShift Lightspeed, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat Ansible Automation Platform 2, Red Hat OpenShift GitOps, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2.6, Red Hat Edge Manager 1.0, Logging Subsystem for Red Hat OpenShift, Cryostat 4 on RHEL 9, Red Hat OpenShift Virtualization 4, Red Hat Edge Manager 1.0, Red Hat Data Grid 8, Self-service automation portal 2, Red Hat Edge Manager 1.1, Red Hat OpenShift GitOps, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Migration Toolkit for Virtualization 2.1, Red Hat Enterprise Linux 10, Red Hat JBoss Enterprise Application Platform 7, Migration Toolkit for Virtualization 2.9, Red Hat build of Apache Camel - HawtIO 4, Red Hat Edge Manager 1.1, Red Hat Openshift Data Foundation 4, OpenShift Lightspeed, Red Hat Single Sign-On 7, Red Hat Edge Manager 1.1, Red Hat OpenShift AI (RHOAI), Red Hat Openshift Data Foundation 4, OpenShift Service Mesh 3, Red Hat Build of Podman Desktop, Red Hat OpenShift Container Platform 4, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift Container Platform 4, Red Hat JBoss Enterprise Application Platform Expansion Pack, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat Trusted Profile Analyzer, Red Hat Openshift Data Foundation 4, Red Hat Ansible Automation Platform 2, Red Hat OpenShift distributed tracing 3.9.2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Container Platform 4, Red Hat Fuse 7, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces 3.27, Migration Toolkit for Applications 8, Red Hat Quay 3, Red Hat AMQ Broker 7, Red Hat Enterprise Linux 9, Red Hat OpenShift Dev Spaces 3.27, Red Hat Process Automation 7, Red Hat Edge Manager 1.1, OpenShift Service Mesh 3, Red Hat Trusted Artifact Signer 1.3, Network Observability Operator, Red Hat Process Automation 7, path-to-regexp, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Enterprise Linux 9, Red Hat build of Apicurio Registry 2, Red Hat Openshift Data Foundation 4, Red Hat Advanced Cluster Security 4, Red Hat Developer Hub 1.8
Provider severity
HIGH
Conflicts
3

CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators. The host create/edit/mobile-bundle/netwo

PUBLISHED
Vendor
juev
Product
nebula-mesh
Provider severity
HIGH
Conflicts
1

CVE-2026-49257

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and table-config mutation, are reachable by any network-adjacent caller. The server proxies these calls using server-side Pinot credentials, producing a confused-deputy condition that yields full read/write

PUBLISHED
Vendor
startreedata
Product
mcp-pinot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49256

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, allowed_tag_groups, or required tag groups could leak to anonymous and unauthorized users through category and group endpoints. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49252

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record. This issue has been fixed in version 10.0.5.

PUBLISHED
Vendor
deepstreamIO
Product
deepstream.io
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4925

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.11.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49248

OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the target is an absolute path. A subsequent file entry in the same archive traverses the symlink, writing to arbitrary server-side locations. This is exploitable by any authenticated user with CI Job write access — no admin interaction required. This is an incomplete fix bypass of CVE-2021-21251 (GHSA-2w6j

PUBLISHED
Vendor
theonedev
Product
onedev
Provider severity
HIGH
Conflicts
0

CVE-2026-49247

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them unsanitized as components of the on-disk filename when persisting client-uploaded log documents. As a result, any authenticated non-admin user can include ../ sequences in the Client field to cause Jellyfin to write attacker-controlled content to arbitrary paths reachable by the Jellyfin service user, wit

PUBLISHED
Vendor
jellyfin
Product
jellyfin
Provider severity
HIGH
Conflicts
0

CVE-2026-49246

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sanitization during playback. Jellyfin treats the MKV file name tag on MKV attachments as trusted and passes it unsanitized into Path.Combine(attachmentFolder, fileName) inside PathManager.GetAttachmentPath. Because .NET's Path.Combine neither normalises .. nor rejects a rooted second argument, a crafted MKV can redirect

PUBLISHED
Vendor
jellyfin
Product
jellyfin
Provider severity
LOW
Conflicts
0

CVE-2026-49241

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vscode/settings.json) without verifying VS Code Workspace Trust state or asking for user consent (located in client/src/client.ts). The client-side extension then passes the parsed settings path as a comm

PUBLISHED
Vendor
angular
Product
angular
Provider severity
HIGH
Conflicts
1

CVE-2026-4924

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token.

PUBLISHED
Vendor
Devolutions
Product
Server
Provider severity
HIGH
Conflicts
0

CVE-2026-49238

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation or dot-dot (..) normalization. A local attacker with root privileges inside a guest virtual machine ca

PUBLISHED
Vendor
Canonical
Product
Multipass
Provider severity
HIGH
Conflicts
0

CVE-2026-49237

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ retain ownership by the installing user and remain writable. Because the root LaunchDaemon (com.canonical.m

PUBLISHED
Vendor
Canonical
Product
Multipass
Provider severity
HIGH
Conflicts
0

CVE-2026-49235

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

PUBLISHED
Vendor
NLnet Labs
Product
Routinator
Provider severity
HIGH
Conflicts
0

CVE-2026-49234

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.

PUBLISHED
Vendor
NLnet Labs
Product
Routinator
Provider severity
HIGH
Conflicts
0

CVE-2026-49233

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

PUBLISHED
Vendor
NLnet Labs
Product
Routinator
Provider severity
HIGH
Conflicts
0

CVE-2026-49232

Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server. This only affects users that make their HTTP or RTR server available to untrusted networks.

PUBLISHED
Vendor
NLnet Labs
Product
Routinator
Provider severity
HIGH
Conflicts
0

CVE-2026-49231

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
LOW
Conflicts
0

CVE-2026-49230

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache APISIX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4923

Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y Safe examples: /*foo-:bar /*foo-:bar-*baz Patches: Upgrade to version 8.4.0. Workarounds: If you are using multiple wildcard parameters, you can check the regex output with a too

PUBLISHED
Vendor
path-to-regexp
Product
path-to-regexp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49229

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session validation path accepts any existing token row that has not expired without checking whether the associated user is still enabled, allowing a disabled user to continue calling authenticated server endpoints. This issue is fixed in version 26.6.0.

PUBLISHED
Vendor
actualbudget
Product
actual
Provider severity
HIGH
Conflicts
0

CVE-2026-49220

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary Javascript in the context of a logged-in Administrative user, resulting in numerous potential issues. The Client header during an AuthenticateByName can contain arbitrary HTML and Javascript, which will then be executed by the Administrative user when visiting the Access tab of the user in question from within the dashboard. T

PUBLISHED
Vendor
jellyfin
Product
jellyfin
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4922

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2026-49219

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49218

A flaw was found in ImageMagick. A missing check in the DCM (Digital Imaging and Communications in Medicine) decoder allows a remote attacker to provide a specially crafted image with invalid dimensions. This can lead to crashes in other operations, resulting in a denial of service (DoS) for the application processing the image.

PUBLISHED
Vendor
Red Hat, Red Hat, ImageMagick
Product
Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 6, ImageMagick
Provider severity
HIGH
Conflicts
2

CVE-2026-49216

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49215

Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+html, but the Accept header is CORS-safelisted and cross-origin fetch() can set it without preflight, allowing forged cross-origin #[LiveAction] requests against a victim session when applications use SameSite=None, credentials: 'include', a permissiv

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
LOW
Conflicts
0

CVE-2026-49214

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is pr

PUBLISHED
Vendor
guzzle
Product
psr7
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49213

TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and private ranges but does not block :: or its expanded form. A workspace editor or creator can configure a server-side HTTP Request block or guarded script fetch to make the Typebot server connect to local HTTP services through safeKy, including flows triggered by

PUBLISHED
Vendor
baptisteArno
Product
typebot.io
Provider severity
HIGH
Conflicts
0

CVE-2026-49212

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0.

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49211

Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by wrapping the client-supplied query in %...% without escaping SQL LIKE wildcards (%, _, \), allowing unauthenticated users to turn the public BaseEntityAutocompleteType endpoint into a broad matcher or blind boolean oracle against every column in default searchable_fields. This issu

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49210

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML as a tag name without escaping or validation, allowing arbitrary HTML, including <script> tags, on any Live Component re-render that contains at least one child component. This issue is fixed

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
LOW
Conflicts
0

CVE-2026-49209

Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue is fixed in versions

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49208

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied relative strings such as now, tomorrow, or +10 years to move a writable, format-less date prop past time-based business logic checks. This issue is fixed in versions 2.36.0 and 3.1.0.

PUBLISHED
Vendor
symfony
Product
ux
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49205

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpoints in the public API. All 4 only call $this->hasValidToken() — which checks a shared API key header, rather than the individual user's role permissions. The following APIs are affected: POST /api/v4.0/

PUBLISHED
Vendor
thorsten
Product
phpMyFAQ
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
HIGH
Conflicts
0

CVE-2026-49201

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

PUBLISHED
Vendor
Acer
Product
Wave 7 router
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

PUBLISHED
Vendor
Acer
Product
Wave 7 router
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4920

The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
jeremyshapiro
Product
Next Date
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49199

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

PUBLISHED
Vendor
Acer
Product
Predator Connect W6x
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49198

Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.

PUBLISHED
Vendor
Acer
Product
Predator Connect W6x
Provider severity
HIGH
Conflicts
0

CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

PUBLISHED
Vendor
Acer
Product
Predator Connect W6x
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49196

The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.

PUBLISHED
Vendor
Acer
Product
Predator Connect W6x
Provider severity
HIGH
Conflicts
0

CVE-2026-49195

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

PUBLISHED
Vendor
Acer
Product
Predator Connect W6x
Provider severity
HIGH
Conflicts
0

CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

PUBLISHED
Vendor
Acer
Product
Connect M6E 5G Portable WiFi Router
Provider severity
CRITICAL
Conflicts
0