By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
5459 published vulnerabilities · page 55 of 55
- CVE-2026-48102LOW 3.1
7-Zip versions 9.11 through 26.00 contain a flaw in how they parse UDF (Universal Disk Format) disc images—used in .iso and .udf files. When processing certain malformed UDF file structures, the parser reads 1 to 3 bytes beyond the allocated memory buffer. This out-of-bounds read occurs during the file open operation and can reveal small amounts of memory content or cause the application to crash. The vulnerability requires user interaction (opening a crafted archive) and affects only information disclosure and stability, not file integrity or system compromise.
- CVE-2026-48587LOW 3.1
Django's cache handling function has a flaw where whitespace in HTTP Vary headers isn't properly cleaned up before comparison. An attacker can exploit this by crafting requests that cause the application to serve cached responses intended for different users, potentially leaking sensitive information. The vulnerability affects Django 5.2 before version 5.2.15 and 6.0 before version 6.0.6, though older unsupported versions may also be vulnerable.
- CVE-2026-49380LOW 3.1
JetBrains TeamCity versions before 2026.1 contain an open redirect vulnerability in the SAML authentication plugin. An attacker could craft a malicious link that, when clicked by a user, redirects them to an attacker-controlled website after authentication. This requires user interaction and offers limited direct impact, but could be chained with phishing or credential harvesting tactics.
- CVE-2026-53663LOW 3.1
React Router versions 7.12.0 through 7.15.0 had incomplete cross-site request forgery (CSRF) protections in Framework Mode. The framework checked for CSRF tokens on POST requests but skipped this validation entirely for PUT, PATCH, and DELETE requests. However, the practical risk is limited because modern browsers already enforce CORS preflight checks and SameSite cookie policies that prevent most cross-origin attacks. The issue is resolved in React Router 7.15.1.
- CVE-2026-56325LOW 3.1
Capgo versions before 12.128.2 have a flaw in how they look up application identifiers when serving preview content. Instead of checking for exact matches, the system uses pattern matching that treats underscore characters as wildcards—similar to how some database queries work. An attacker with an account on Capgo can exploit this by creating apps with slightly different names that leverage these wildcard behaviors, potentially breaking preview functionality for legitimate applications or causing confusion about which app is being accessed.
- CVE-2026-6873LOW 3.1
Django's signed cookie verification contains a cryptographic flaw in how it generates salts for cookie signatures. By exploiting collisions in salt derivation, an authenticated attacker can repurpose a legitimately signed cookie in an unintended context—for example, using a cookie signed for one feature to authenticate requests for a different feature. This is a low-severity issue requiring prior authentication and careful attack setup, but it undermines the integrity guarantee that signed cookies are meant to provide.
- CVE-2026-7666LOW 3.1
Django's email system has a vulnerability that can expose email content over the network under specific conditions. When Django is configured to silently ignore mail delivery errors (`fail_silently=True`) and a secure connection attempt fails, the system may reuse a partially-initialized connection that falls back to unencrypted communication. An attacker positioned on the network path between your application and the mail server could potentially read email content in transit. This requires multiple conditions to align: configuration settings, network positioning, and a failed STARTTLS handshake.
- CVE-2026-8404LOW 3.1
Django's cache middleware has a case-sensitivity bug in how it reads `Cache-Control` directives. When a web application uses uppercase or mixed-case values in `Cache-Control` headers (e.g., `PRIVATE` instead of `private`), the middleware fails to recognize them as valid directives. This causes responses that should not be cached to be cached anyway, potentially exposing sensitive data to unauthorized users who can trigger cache hits.
- CVE-2026-9920LOW 3.1
Google Chrome on Android contains a vulnerability in GPU memory handling that could allow an attacker who has already compromised the browser's renderer process to access sensitive data from websites that should be isolated from each other. The vulnerability stems from uninitialized memory in the GPU code path, which under specific conditions could leak cross-origin data through a malicious webpage. This requires the renderer process to be compromised first, making it a secondary exploitation step rather than a direct entry point.
- CVE-2026-9944LOW 3.1
CVE-2026-9944 is a memory safety issue in the ANGLE graphics library used by Google Chrome. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to leak sensitive data from other websites or origins. The vulnerability requires the renderer to be compromised first, limiting the attack surface, but the data leakage potential is real once that initial foothold exists. Chrome versions before 148.0.7778.216 are vulnerable on Windows, macOS, and Linux.
- CVE-2026-9950LOW 3.1
A same-origin policy bypass vulnerability exists in Google Chrome on iOS versions prior to 148.0.7778.216. The flaw stems from insufficient validation of untrusted input that allows an attacker who has already compromised Chrome's renderer process to craft a malicious HTML page that circumvents browser security boundaries. This means an attacker could potentially access data or perform actions from a different website origin than the one a user is visiting, but only if the renderer process has already been compromised through another attack vector.
- CVE-2026-9959LOW 3.1
A race condition in WebRTC functionality within Google Chrome on Windows allows an attacker to leak data across origin boundaries. The vulnerability requires user interaction (clicking on a crafted HTML page) and is difficult to exploit reliably due to timing constraints. While the underlying issue is rated High severity by Chromium, the CVSS 3.1 score of 3.1 reflects the practical barriers to exploitation and limited scope—an attacker can extract sensitive information, but cannot modify data or disrupt service.
- CVE-2026-9991LOW 3.1
A vulnerability in Google Chrome's media handling on Windows allows an attacker who has already compromised the browser's renderer process to extract sensitive data across security boundaries. The attacker would need to host a malicious webpage and trick a user into visiting it while the renderer is already under their control. The exposure is information disclosure—no system takeover or crashes—and the barrier to exploitation is relatively high because the attacker must first achieve renderer compromise.
- CVE-2026-49358LOW 3.0
PhpWeasyPrint, a PHP library used to generate PDFs from URLs or HTML content, contains a flaw in how it manages temporary files. Before version 2.6.0, the list of temporary files is stored in a public variable that any code in the application can modify. When the library shuts down, it deletes every file listed in that variable without checking whether those files actually belong to the temporary folder. This means an attacker with code execution could trick the library into deleting arbitrary files on the system by adding them to the list. The vulnerability requires an attacker to have already compromised the application or have another way to run PHP code in the same process.
- CVE-2024-58350LOW 2.9
Ghidra, the reverse-engineering framework maintained by the NSA, contains a memory management flaw that can cause the application to hang or crash during shutdown. The problem stems from improperly ordered cleanup of internal components, where the program attempts to access memory that has already been freed. An attacker with local access can trigger this condition, resulting in a denial-of-service effect. This is a low-severity issue with limited real-world impact, as it requires local execution and only affects availability during the shutdown phase.
- CVE-2026-39199LOW 2.9
snes9x version 1.63 contains a flaw that allows an attacker to cause a denial of service by supplying a maliciously crafted .ups file. The vulnerability involves writing data outside the intended memory boundaries, but exploitation requires local access and specific conditions to be met. This is a low-severity issue primarily affecting users who process untrusted patch files on systems running the vulnerable version.
- CVE-2026-39894LOW 2.9
Cacti, an open-source performance monitoring framework, has a data integrity flaw in versions 1.2.30 and earlier. The issue stems from how the system handles decimal numbers when the server is configured with certain locales (like German) that use commas instead of periods as decimal separators. When Cacti sends metric data to RRDtool for storage, locale-dependent formatting causes the decimal separator to change from a period to a comma, which RRDtool doesn't recognize. This causes monitoring data to be misaligned or discarded entirely. The flaw requires specific server locale misconfiguration and is not remotely exploitable, but it silently corrupts your metrics—potentially masking real performance issues. The fix is available in version 1.2.31.
- CVE-2026-57062LOW 2.9
GnuPG's gpgsm tool, which handles digitally signed and encrypted messages in a standard format called CMS (Cryptographic Message Syntax), has a flaw in how it validates a specific cryptographic parameter. When using AES-GCM encryption, the tool should reject messages where a security tag is shorter than 12 bytes, but instead it incorrectly accepts messages with a 4-byte tag. This laxness in validation could allow an attacker to forge or tamper with encrypted messages in ways that might not be detected, though the practical impact is limited and requires local access.
- CVE-2026-10078LOW 2.7
Quay's config-tool contains a flaw in how it handles GitLab OAuth setup. When administrators configure GitLab as an identity provider, sensitive credentials (client ID and secret) are passed in plaintext within the URL query string of POST requests. This is problematic because these credentials can be logged by web servers, reverse proxies, load balancers, and monitoring systems—anywhere that records HTTP request details. An attacker who gains access to these logs could extract the credentials and impersonate Quay's OAuth client to GitLab, potentially gaining unauthorized access to repositories or other GitLab resources.
- CVE-2026-10753LOW 2.7
The Site Kit by Google WordPress plugin before version 1.176.0 contains a privilege escalation vulnerability affecting its REST API. Users with Editor-level access or those granted dashboard sharing permissions can modify plugin settings that should be restricted to administrators only. This occurs because the REST API endpoint lacks proper role-based access controls. While the technical impact is limited to unauthorized configuration changes, the vulnerability could allow lower-privileged users to alter site-wide plugin behavior without administrative approval.
- CVE-2026-12102LOW 2.7
A WordPress plugin called UsersWP has a flaw that allows editors and higher-level users to delete profile images (avatars and banners) belonging to any other user, including administrators. The vulnerability exists because the plugin doesn't properly validate which user a person is trying to modify when they submit a request to change or remove an image. While the impact is limited to image deletion and requires elevated account privileges to exploit, it could be used to deface user profiles or cause minor disruption.
- CVE-2026-12211LOW 2.7
A path traversal vulnerability has been discovered in Intelbras iNVU 7016 FT running firmware version 3.004.00IB000.0.T (Build 2025-09-26). An attacker with high-level administrative privileges can manipulate requests to the web interface's /RPC2_Loadfile/syslog/ endpoint to access files outside their intended directory. The vulnerability requires authentication and has limited confidentiality impact, but the vendor has already released a patched version. Public exploit code is available, though practical exploitation remains constrained by privilege requirements.
- CVE-2026-44367LOW 2.7
Klaw, a Kafka topic management and governance platform, contains a vulnerability in how it handles usernames during registration and login. The system doesn't consistently apply case sensitivity rules—treating 'Admin' and 'admin' as different or the same depending on the operation—which allows authenticated users with administrative privileges to deliberately lock out accounts or trigger denial of service conditions. This is a low-severity issue requiring administrative access to exploit, but it can impact operational availability if administrators use it maliciously or if the inconsistency is exploited in targeted attacks. The flaw was fixed in version 2.10.4.
- CVE-2026-45076LOW 2.7
Synapse, an open-source Matrix homeserver implementation used for federated messaging, contains a flaw in how it handles room history in cross-server deployments. Malicious homeservers can craft specially formed room events that cause Synapse instances to withhold historical messages from clients requesting older conversation data. Users may see incomplete chat histories or missing messages when paginating through room archives. This is a low-severity issue because it requires a compromised or malicious federated peer and affects data availability rather than confidentiality or integrity.
- CVE-2026-49979LOW 2.7
Appsmith versions before 1.99 contain a vulnerability in the test email functionality that allows high-privileged users to perform internal network reconnaissance. When an authenticated admin tests the email configuration, the application accepts custom SMTP server addresses without validating whether they point to internal IP ranges. An attacker with admin access can abuse this to probe internal services, discover what's running on specific ports, and gather system information through detailed error messages—all without leaving the admin panel. The vulnerability requires existing admin credentials, limiting its practical attack scope.
- CVE-2026-9088LOW 2.7
Keycloak contains a flaw in how it enforces user profile visibility rules for delegated administrators. An admin with permission to view group memberships and users can circumvent access controls by querying the group members endpoint, allowing them to see sensitive user attributes that should be hidden from them. This is a controlled-access issue—the attack requires administrative privileges and does not affect regular users or public-facing functionality.
- CVE-2026-45154LOW 2.6
Nextcloud, an open-source content collaboration platform, contains a flaw affecting versions 2.6.0 through 4.2.x that allows guest users to retrieve deleted collaborative pages from the trash when the parent collective is shared in view-only mode. An attacker with guest access could circumvent intended deletion by directly accessing removed content, though the exposure is limited to information disclosure and requires prior access to the shared collective. The vulnerability has been resolved in version 4.3.0.
- CVE-2026-45155LOW 2.6
Nextcloud Server contains a flaw in its circles feature that allows authenticated users to add unknown circles to other circles by directly referencing their IDs, potentially enabling membership tracking. While circle IDs are designed with high complexity (62^15 combinations), if an attacker obtains a valid circle ID through other means, they could exploit this missing access control. The vulnerability requires an authenticated session and user interaction to exploit, making opportunistic attacks unlikely but targeted attacks possible if circle IDs are discovered.
- CVE-2026-9694LOW 2.6
GitLab CE/EE contains a vulnerability in its Service Desk feature that allows an unauthenticated attacker to impersonate the GitLab Support Bot through a specially crafted email reply. The attacker can inject arbitrary content into email template processing under specific conditions. While the vulnerability requires certain setup conditions and user interaction to exploit, it could lead to content injection that misleads users interacting with the support system.
- CVE-2026-10783LOW 2.5
A weakness in Gradio 6.14.0's audio caching function allows a local user with limited privileges to potentially access confidential information through use of a weak cryptographic hash. The attack is technically difficult to execute and requires hands-on access to the system. While a public exploit exists, real-world exploitation remains unlikely due to high complexity requirements and low impact scope.
- CVE-2026-11481LOW 2.5
A weakness in the grepai project (versions up to 0.35.0) allows a local user with login privileges to manipulate how the Postgres Embedding Cache stores and retrieves content hashes, potentially causing the system to use weak cryptographic hashing. The vulnerability requires significant technical knowledge to exploit and poses limited immediate risk, but should be addressed through the pending patch once merged.
- CVE-2026-54326LOW 2.5
Pi is a lightweight terminal-based code editor that lets developers export their work sessions as static HTML files for documentation or sharing. Between versions 0.74.0 and 0.78.0, the application failed to properly validate link and image URLs in these exports, allowing potentially harmful URLs to slip through. An attacker could craft a malicious Markdown file that, when exported to HTML, would contain dangerous links—such as those beginning with 'javascript:' or other browser-executable schemes. The flaw exploited a bypass technique: sneaking C0 control characters (invisible, non-printing characters) into the URL scheme to fool the security filter. Browsers automatically clean up these hidden characters before acting on URLs, meaning the malicious intent survives. This is a low-severity issue because it requires local access to the Pi application and user interaction to trigger. It was patched in version 0.78.1.
- CVE-2026-10112LOW 2.4
CVE-2026-10112 is a stored or reflected cross-site scripting (XSS) vulnerability in the Dashboard Page component of STUDENT-MANAGEMENT-SYSTEM version 1.0. An attacker with high privileges can inject malicious scripts through the Name parameter, which are then executed in the browsers of users who view the affected page. The vulnerability requires user interaction and has a low CVSS score of 2.4, but exploitation has already been disclosed publicly.
- CVE-2026-10514LOW 2.4
A cross-site scripting (XSS) vulnerability exists in CordysCRM versions up to 1.6.2. The flaw is located in a request parameter handling component and allows attackers with administrative privileges to inject malicious scripts that execute in users' browsers. While public exploit code is available, the attack requires both high-level credentials and user interaction (such as clicking a malicious link), significantly limiting real-world risk. Upgrading to version 1.7.0 resolves the issue.
- CVE-2026-10529LOW 2.4
A cross-site scripting (XSS) vulnerability has been discovered in westboy CicadasCMS affecting the Task Scheduling Management Module. The flaw exists in the ScheduleJobController component and can be triggered by an authenticated user with elevated privileges through a specially crafted request. While the vulnerability requires administrative or high-privilege access to exploit, the presence of user interaction (rendering) combined with public availability of exploit details elevates attention. The CMS uses a rolling release model, making definitive version tracking difficult, though the affected commit hash has been identified.
- CVE-2026-11338LOW 2.4
A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Ship Ferry Ticket Reservation System version 1.0. An authenticated administrative user with high privileges can inject malicious JavaScript into the Username parameter on the user management page, which executes in the browsers of other users who view the manipulated content. The vulnerability requires user interaction and administrative access to trigger, limiting its immediate exposure but potentially enabling unauthorized account manipulation or credential theft within administrative workflows.
- CVE-2026-11434LOW 2.4
FluentCMS version 0.0.5 contains a cross-site scripting (XSS) vulnerability in its Blocks Plugin, specifically within the /admin/blocks file. An authenticated administrator with high privileges can inject malicious scripts that execute in the browsers of other users viewing the affected page. The vulnerability requires user interaction (such as clicking a link) to trigger. Public exploit code is available, though the low CVSS score reflects the requirement for high-privilege authentication and user interaction to succeed.
- CVE-2026-11468LOW 2.4
A cross-site scripting (XSS) vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An authenticated administrator with high privileges can inject malicious scripts through the room_types page by manipulating the room parameter. When another user visits the affected page, the injected script executes in their browser, potentially allowing session hijacking, credential theft, or malware distribution. The vulnerability requires both administrative access to initiate the attack and user interaction (clicking a link or visiting a crafted URL) for the payload to execute. While the CVSS score is low, the healthcare context and potential for patient data exposure warrant careful attention.
- CVE-2026-11491LOW 2.4
CodeAstro Human Resource Management System version 1.0 contains a stored cross-site scripting (XSS) vulnerability in its Notice Board Management feature. An attacker with high privileges can inject malicious JavaScript into the Notice Title field, which is then executed in the browsers of other users viewing that notice. The vulnerability requires user interaction (a victim must view the affected notice) and has already been disclosed publicly with exploit code available.
- CVE-2026-12202LOW 2.4
A stored or reflected cross-site scripting (XSS) vulnerability exists in Intelliants Subrion CMS versions up to 4.0.3. The flaw resides in the Blocks Endpoint component, where improper handling of CSS class name parameters allows an attacker to inject malicious scripts. Because the vulnerability requires administrative privileges to exploit and user interaction is needed for the attack to succeed, the overall risk is low. However, the public disclosure of this issue means threat actors now have detailed information about how to craft attacks.
- CVE-2026-41986LOW 2.4
CVE-2026-41986 is a logic bypass vulnerability affecting file system operations. An attacker with physical access to a system could exploit this flaw to disrupt availability—for example, by manipulating file system behavior to cause denial of service. The vulnerability requires direct physical interaction with the machine and carries a low severity rating. The primary concern is operational disruption rather than data theft or system compromise.
- CVE-2026-49317LOW 2.4
The 2025 Indian Motorcycle Scout Bobber + Tech infotainment system has a logic flaw in how it initializes during boot. The system is supposed to require a PIN to unlock, but it uses a problematic shortcut: it checks whether it detects wireless messages from the motorcycle's Wireless Control Module (WCM) during startup. If those messages are absent, the system assumes no immobilizer is present and skips the PIN screen entirely, granting immediate access to the infotainment interface. An attacker with adjacent network access can silence the WCM during the boot window—using techniques like a CAN bus-off attack—to trick the system into thinking the immobilizer is not installed, thereby bypassing the PIN protection that should guard the interface.
- CVE-2026-49318LOW 2.4
A flaw in the 2025 Indian Motorcycle Scout Bobber + Tech's infotainment system allows someone with physical proximity to the motorcycle to unlock the digital display without entering the correct PIN. The system incorrectly assumes that if it doesn't detect wireless signals from a control module during startup, no security PIN is needed. An attacker can exploit this by blocking those signals during the boot process, causing the system to skip the PIN screen entirely and display the full user interface.
- CVE-2026-9610LOW 2.3
IBM Datacap and Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9 contain a flaw where certain features or data are accessible directly via URL without proper authorization checks, even though those features are not advertised in the user interface. An attacker with local access and elevated privileges could bypass intended security boundaries to view sensitive information.
- CVE-2026-12567LOW 2.2
CVE-2026-12567 is a local privilege escalation flaw in the github_workflows module that fails to validate repository names for symlink attacks. An attacker with local access to the scan directory can create a malicious symlink at a predictable output location, tricking the module into writing workflow data wherever the attacker directs. This requires local system access and user interaction, limiting immediate blast radius but creating a path for data exfiltration or code injection in multi-user or CI/CD environments.
- CVE-2026-50266LOW 2.2
A flaw in OpenStack Neutron versions before 28.0.1 allows project managers to perform network spoofing attacks on shared networks. The vulnerability stems from overly permissive role-based access control (RBAC) policies that allow any project manager to create or modify ports on networks they don't own, and crucially, to assign those ports special "trusted" network service identities (like DHCP servers). This bypasses normal anti-spoofing rules and security group protections, enabling attackers to spoof DHCP, MAC, or IP addresses to target other tenants sharing the same network. This is a reintroduction of a vulnerability that was supposedly fixed nearly a decade ago.
- CVE-2026-54327LOW 2.2
Pi is a lightweight terminal-based coding tool that manages API authentication through a local configuration file. Between versions 0.74.0 and 0.78.1, a timing vulnerability could temporarily expose stored API keys and OAuth tokens with overly permissive file access before the application locked down security settings. This window is extremely brief but theoretically allows a local user with active session privileges to read credentials meant to be private. The issue has been patched in version 0.78.1.
- CVE-2026-45403LOW 2.0
AnythingLLM versions before 1.13.0 contain a path traversal vulnerability in the agent filesystem copy tool. When copying files, the application only validates the top-level source and destination directories but fails to validate nested files or reject symbolic links. An attacker with high privileges could create or exploit a symlink nested within an allowed source directory to read files outside the intended filesystem boundaries and copy them to an allowed destination, potentially exposing sensitive data. The vulnerability requires high user privileges, complex conditions, and user interaction to exploit, making practical real-world abuse unlikely despite the core weakness.
- CVE-2026-46549LOW 2.0
NocoDB, a spreadsheet-like database platform, contained a flaw in how it handled OAuth token permissions. When administrators issued OAuth tokens with intentionally restricted scopes—such as limiting access to specific features or databases—the system failed to actually enforce those restrictions. A user with such a restricted token could gain access to resources and perform actions far beyond what the token was meant to allow, effectively inheriting the full permissions of the underlying user account. This issue has been patched in version 2026.04.1.
- CVE-2026-47713LOW 2.0
AnythingLLM versions before 1.13.0 contain a token persistence flaw that can leak sensitive data when administrators migrate from single-user to multi-user mode. A mobile device token issued in single-user mode may remain valid after the migration, allowing it to bypass user-scoping controls and access workspaces and chat content belonging to other users. The vulnerability requires an attacker to have had a legitimate mobile device token before the migration, then exploit it post-migration in the multi-user environment.
- CVE-2026-11786LOW 1.9
A parsing flaw in 389 Directory Server can cause the LDIF (LDAP Data Interchange Format) parser to read past the boundary of allocated memory when it encounters attribute types ending with semicolons during database imports. The defect is detectable only under memory instrumentation tools (such as AddressSanitizer) and does not cause immediate functional failure or crashes under normal operation. This is a low-severity out-of-bounds read affecting local, high-privileged operations.
- CVE-2026-50268LOW 1.9
Steeltoe.Configuration.Encryption versions 4.0.0 through 4.1.0 contain a configuration bug where the OAEP encryption algorithm setting does not work as intended. When administrators configure the system to use OAEP (a stronger RSA encryption variant), the software incorrectly falls back to the weaker PKCS#1 v1.5 algorithm instead. This occurs due to an incorrect transformation string passed to the BouncyCastle cryptographic library. The vulnerability requires local access and administrative privileges to exploit, making it a low-risk issue in most environments. Version 4.2.0 corrects this defect.
- CVE-2026-12065LOW 1.8
A vulnerability in the Groww Stock, Mutual Fund, and Gold app (Android versions up to 20260805) allows attackers with physical access to a device to bypass authorization checks on custom URL schemes handled by the app's WebView component. An attacker would need to be present at the device and have some level of authentication context, making this a low-risk issue in typical operational environments. The issue affects the app's custom protocol handlers, which are entry points for inter-app communication on Android.
- CVE-2026-48617LOW 1.8
Node.js versions 22, 24, and 26 contain a flaw in how they enforce the Permission Model security feature. Specifically, the `process.report.writeReport()` function does not properly validate file paths, allowing an authenticated local attacker with high privileges to bypass the intended security boundary. The risk is limited to integrity impact in this case, though the vulnerability could expose sensitive information under certain configurations. This is a low-severity issue that requires local access and user interaction to exploit.
- CVE-2026-12635NONE 0.0
GitLab has patched a server-side request forgery (SSRF) vulnerability affecting multiple versions of GitLab Community and Enterprise editions. The flaw allowed authenticated users with maintainer-level permissions to bypass URL validation during mirror synchronization, potentially enabling them to make requests to internal network resources. The vulnerability required specific conditions and user interaction through the mirror sync feature, limiting its practical exposure.
- CVE-2026-44956NONE 0.0
CVE-2026-44956 is a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious code through their Full Name field. The injected payload persists in system-generated emails, which are stored in the userlog table. When an administrator views the email content via the userlog-details.php page, the unescaped JavaScript executes in their browser, potentially compromising admin accounts or enabling unauthorized actions. The vulnerability has been patched by adding proper output sanitization to the userlog details display.
- CVE-2026-44960NONE 0.0
A stored cross-site scripting (XSS) vulnerability exists in the audit log viewer that allows an attacker to inject malicious JavaScript through usernames. When an administrator views audit log details, any embedded script payload in a username would execute in their browser due to insufficient output sanitization. The vendor has patched this by adding proper output escaping to the audit log display.
- CVE-2026-44961NONE 0.0
CVE-2026-44961 is a validation bypass in an XML-RPC API's user creation method that was inadvertently introduced when patching a previous vulnerability. The flaw allows attackers to craft usernames that bypass security checks, enabling account impersonation or injection of malicious scripts. Because the vulnerability has no CVSS score assigned and is not listed on CISA's Known Exploited Vulnerabilities catalog, it appears to be a localized or low-impact issue at this time, though the authentication context and data exposure potential warrant attention.
- CVE-2026-55611NONE 0.0
AnythingLLM versions 1.11.1 through 1.14.0 contain an authorization flaw in the file embedding workflow. Authenticated managers or admins can delete parsed files belonging to other users across any workspace—including workspaces they have no membership in—by guessing or enumerating file IDs. The vulnerability exists because the delete operation bypasses ownership verification, executing even when the access control check fails. Version 1.14.1 fixes this issue.