A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
CVSSv3.1 8.8 (HIGH)
CWECWE 470VNDCraftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 16:17Z
HIGH
CVE-2026-4129 — There: is an improper access control vulnerability in NI SystemLink that may allow an
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
CVSSv3.1 8.1 (HIGH)
CWECWE 862VNDThereTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 16:00Z
HIGH
Unmasking SCCM Application Execution
SpecterOps·specterops.io
SpecterOps researcher Joshua Prager details the technical mechanics of SCCM application execution versus script execution, revealing that applications execute through WmiPrvSE.exe rather than CcmExec.exe. The research traces the DLL chain (AppProvider.dll → ScriptHandler.dll → AppExcnLib.dll → ccmcore.dll) that ultimately calls CreateProcessW, and provides detection guidance for identifying this stealthier execution path that bypasses existing script-based SCCM detection.
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation in mutation resolvers.
CVSSv3.1 8.3 (HIGH)
CWECWE 269VNDOpenpanelTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88890 — OpenPanel: through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
CVSSv3.1 8.5 (HIGH)
CWECWE 89VNDOpenpanelTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88887 — Renovate: When listing tags/digests for a container image, Renovate follows pagination links supplied by the
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore specify a Link header pointing to an attacker-controlled host and receive the cre
CVSSv3.1 8.6 (HIGH)
CWECWE 601VNDRenovateTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88882 — Renovate: Exploitation requires the remote registry to be malicious or compromised; such a registry would
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the configured registry. Registry credentials are attached to the request for the 'ne
CVSSv3.1 8.6 (HIGH)
CWECWE 601VNDRenovateTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88881 — Renovate: Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL is not validated against the host originally contacted, a malicious or compromised GitHub server can return a `Link` header pointing to an attacker-controlled h
CVSSv3.1 8.6 (HIGH)
CWECWE 601VNDRenovateTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88880 — Renovate: before 44.11.3 fails to validate Link header destinations when following GitLab server pagination
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
CVSSv3.1 8.6 (HIGH)
CWECWE 601VNDRenovateTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
3d ago
2026-09-10 14:17Z
CRIT
CVE-2026-88877 — Traefik: In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider creates an additional 'sibling' router that matches on the host alone, carries only the RedirectRegex middleware, and still points at the parent router's protected backend service. Becau
CVSSv3.1 9.8 (CRITICAL)
CWECWE 639VNDTraefikTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3d ago
2026-09-10 14:17Z
CRIT
CVE-2026-88869 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execution of arbitrary JavaScript in an administrator's browser session.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 79VNDAvideoTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88868 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDAvideoTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88867 — WWBN: AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site
WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName() and Category::setIconClass(), which store the values without sanitization (setName only truncates to 45 characters). The category name is later echoed as HTML text and iconClass is echoed into a class attribute in view/modeYout
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDWwbnTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88866 — WWBN: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session.
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDWwbnTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88865 — AVideo: through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.
CVSSv3.1 8.1 (HIGH)
CWECWE 639VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 14:17Z
CRIT
CVE-2026-88864 — Capgo: (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provider creation via the Supabase Management API, DNS TXT domain-ownership verificatio
CVSSv3.1 9.1 (CRITICAL)
CWECWE 284VNDCapgoTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88863 — This allows privilege escalation resulting in full administrative control over the organization's apps, channels
capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the org.invite_user permission (e.g., an org_member) can invite an external user as o
CVSSv3.1 8.1 (HIGH)
CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88862 — Capgo: (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-organization (e.g., app-scoped) RBAC binding and validateSubkeyUser() only compares
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDCapgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-88861 — Capgo: (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance
CVSSv3.1 8.3 (HIGH)
CWECWE 288VNDCapgoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3d ago
2026-09-10 14:17Z
HIGH
CVE-2026-85217 — A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through
A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.
CVSSv3.1 8.6 (HIGH)