VU#748485: Unauthenticated configuration modification vulnerability in Central Office Services - Content Hosting Component

2026-04-27T20:52:16Z8308279e61a00fc76fbb5b937e0d787a8bb68f13e7774c7100f52f1597292d03
configuration-modificationdata-exfiltrationdecompression-bombggufheap-buffer-overflowinformation-disclosureinteger-overflowjinja2-sstimedical-imagingmodel-uploadpdfreflected-xssremote-code-executionsandbox-escapeunauthenticated

What happened

Collection of multiple high-impact vulnerabilities across diverse products. Notable issues include an unauthenticated configuration-modification endpoint in DRC INSIGHT Central Office Services (CVE-2026-5756) enabling data exfiltration and traffic redirection; an unauthenticated GGUF model-upload memory disclosure in Ollama (CVE-2026-5757); reflected XSS in Radware Alteon (CVE-2026-5754); sandbox escape leading to root RCE in Terrarium (CVE-2026-5752); Jinja2 SSTI-based RCE in SGLang via malicious model files (CVE-2026-5760); multiple heap/overflow and decompression/zip memory issues in Orthoc

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
8308279e61a00fc76fbb5b937e0d787a8bb68f13e7774c7100f52f1597292d03
Enrichment time
2026-04-27T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.