THREAT OPS › Threat News
Threat Intelligence News
11685 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [qilin] Absolute Consultancy Services posted to leak siteransomware_live · 2026-08-30
- [qilin] Black Cat Engineering Construction Wll posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82635 (HIGH 8.8) — Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolvesnvd · 2026-08-30
- [NVD] CVE-2026-82634 (MEDIUM 6.5) — Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary SEnvd · 2026-08-30
- [NVD] CVE-2026-82633 (MEDIUM 4.3) — Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers tnvd · 2026-08-30
- [NVD] CVE-2026-82543 (HIGH 7.3) — A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit Handler. Performing a manipulation results in race condition. It is possible to initiate the attacknvd · 2026-08-30
- [NVD] CVE-2026-82542 (CRITICAL 10.0) — A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to bnvd · 2026-08-30
- [NVD] CVE-2026-82541 (MEDIUM 6.3) — A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The envd · 2026-08-30
- [NVD] CVE-2026-82540 (MEDIUM 6.3) — A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publiclynvd · 2026-08-30
- [NVD] CVE-2026-81318 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5 renvd · 2026-08-30
- [NVD] CVE-2026-81316 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary. AshSql.Aggregate.differentnvd · 2026-08-30
- [NVD] CVE-2026-80227 — Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse)nvd · 2026-08-30
- [NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an anvd · 2026-08-30
- [NVD] CVE-2026-78228 — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action onnvd · 2026-08-30
- [NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.nvd · 2026-08-30
- [NVD] CVE-2026-77454 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort. AshSql.Join.related_query/3nvd · 2026-08-30
- [NVD] CVE-2026-82539 (CRITICAL 9.1) — A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remonvd · 2026-08-30
- [NVD] CVE-2026-82488 (LOW 3.5) — A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicnvd · 2026-08-30
- [NVD] CVE-2026-82487 (MEDIUM 6.3) — A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted earlynvd · 2026-08-30
- [NVD] CVE-2026-82486 (MEDIUM 5.0) — A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is nvd · 2026-08-30
- [thegentlemen] Glassdoor posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] G R Infraprojects posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Northwest Trophy posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] General Gruppo posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Ixa Systems posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Tecno Accion posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Probe Test System posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] SUNSEA posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Thai Film Industries PCL posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Adkisson Group posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] ESB Puerto Rico Corp posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Nutrypollo posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Brebur posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] MB Associates posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Exacta Optech Labcenter posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Servicios Aereos Estrella posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82485 (MEDIUM 6.3) — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploitnvd · 2026-08-30
- [NVD] CVE-2026-82484 (MEDIUM 6.3) — A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be unvd · 2026-08-30
- [threeam] wmdn.net posted to leak siteransomware_live · 2026-08-30
- [Black X] FE CREDIT posted to leak siteransomware_live · 2026-08-30
- [Black X] i-one posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82483 (LOW 3.5) — A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotelynvd · 2026-08-30
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoorthehackernews · 2026-08-30
- [NVD] CVE-2026-82482 (LOW 3.5) — A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The anvd · 2026-08-30
- [NVD] CVE-2026-81766 — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to instnvd · 2026-08-30
- [NVD] CVE-2026-81660 — The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perfonvd · 2026-08-30
- [NVD] CVE-2026-78364 — The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege unvd · 2026-08-30
- [NVD] CVE-2026-76585 — The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.nvd · 2026-08-30
- [NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore direnvd · 2026-08-30
- [NVD] CVE-2026-14835 — The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contribunvd · 2026-08-30
- [NVD] CVE-2026-14307 — The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victimnvd · 2026-08-30
- CyberDanube Security Research 20260611-0 | Multiple Denial of Service Vulnerabilities in Dahua IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC Camera Seriesfulldisclosure · 2026-08-30
- JSON Deserialiser Unconstrained Resource Consumption Proof of Conceptfulldisclosure · 2026-08-30
- [NVD] CVE-2026-82480 (HIGH 7.4) — A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize renvd · 2026-08-30
- [NVD] CVE-2026-82479 (MEDIUM 6.3) — A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from winvd · 2026-08-30
- [NVD] CVE-2026-82478 (HIGH 7.3) — A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-bnvd · 2026-08-30
- [NVD] CVE-2026-15980 (CRITICAL 9.8) — The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unautnvd · 2026-08-30
- [NVD] CVE-2026-77846 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. AshSqlite.Sqnvd · 2026-08-30
- [NVD] CVE-2026-75759 — Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted nvd · 2026-08-30
- [NVD] CVE-2026-82562 (LOW 3.7) — ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), nvd · 2026-08-30
- [NVD] CVE-2026-77970 — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore nvd · 2026-08-30
- [NVD] CVE-2026-77831 — Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking, AshPnvd · 2026-08-30
- [NVD] CVE-2026-75847 — Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in thnvd · 2026-08-30
- [NVD] CVE-2026-82417 (MEDIUM 5.3) — ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is tnvd · 2026-08-30
- [NVD] CVE-2026-82424 (MEDIUM 6.3) — A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The nvd · 2026-08-29
- [NVD] CVE-2026-82423 (MEDIUM 5.4) — A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is pnvd · 2026-08-29
- [NVD] CVE-2026-82422 (MEDIUM 6.3) — A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/emp_del.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to nvd · 2026-08-29
- [NVD] CVE-2026-82421 (MEDIUM 6.3) — A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly avanvd · 2026-08-29
- [shinyhunters] Neogen Corporation posted to leak siteransomware_live · 2026-08-29
- graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via full-schema "did you mean" suggestion scanoss_sec · 2026-08-29
- graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS from a single syntax erroross_sec · 2026-08-29
- [NVD] CVE-2026-15369 (CRITICAL 9.8) — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Stonvd · 2026-08-29
- Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoSoss_sec · 2026-08-29
- [qilin] Bandit Industries posted to leak siteransomware_live · 2026-08-29
- [NVD] CVE-2026-75807 (HIGH 7.5) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_sanvd · 2026-08-29
- [qilin] LAPoco Architects posted to leak siteransomware_live · 2026-08-29
- [NVD] CVE-2026-82476 (MEDIUM 5.3) — Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata fetcher, allowing unauthenticated attackers to bypass IP validation. Attackers can make the server request internal hosts in that range including cloud metadata nvd · 2026-08-29
- [NVD] CVE-2026-82475 (HIGH 8.1) — iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to reanvd · 2026-08-29
- [NVD] CVE-2026-82474 (HIGH 7.8) — Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.nvd · 2026-08-29
- [NVD] CVE-2026-82473 (HIGH 8.2) — KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking nvd · 2026-08-29
- [NVD] CVE-2026-82472 (HIGH 7.5) — Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database witnvd · 2026-08-29
- [NVD] CVE-2026-82470 (MEDIUM 5.4) — Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor.nvd · 2026-08-29
- [NVD] CVE-2026-82469 (MEDIUM 5.4) — Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, nvd · 2026-08-29
- [NVD] CVE-2026-82468 (MEDIUM 4.7) — Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and forcenvd · 2026-08-29
- [NVD] CVE-2026-82467 (MEDIUM 4.7) — Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-renvd · 2026-08-29
- [NVD] CVE-2026-82466 (HIGH 8.7) — Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of vanvd · 2026-08-29
- [NVD] CVE-2026-82465 (MEDIUM 5.3) — pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowing an unauthenticated attacker to submit anvd · 2026-08-29
- [NVD] CVE-2026-82464 (MEDIUM 6.1) — pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed external hosts that browsers normalize into nvd · 2026-08-29
- [NVD] CVE-2026-82463 (HIGH 8.1) — pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic pnvd · 2026-08-29
- [NVD] CVE-2026-82462 (MEDIUM 6.5) — pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verinvd · 2026-08-29
- [NVD] CVE-2026-82461 (HIGH 8.1) — pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications rnvd · 2026-08-29
- [NVD] CVE-2026-82460 (CRITICAL 9.8) — Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured rootnvd · 2026-08-29
- Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEthehackernews · 2026-08-29
- [emperador] Uniguacu posted to leak siteransomware_live · 2026-08-29
- [qilin] Neumaticos Corral S.A. posted to leak siteransomware_live · 2026-08-29
- [NVD] CVE-2026-82457 (HIGH 7.8) — su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec nvd · 2026-08-29
- [NVD] CVE-2026-82456 (CRITICAL 10.0) — argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to creatnvd · 2026-08-29
- [NVD] CVE-2026-82455 (HIGH 7.1) — RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory cannvd · 2026-08-29
- [NVD] CVE-2026-82454 (CRITICAL 9.1) — The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwtnvd · 2026-08-29
- [NVD] CVE-2026-82452 (CRITICAL 9.8) — rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessinnvd · 2026-08-29