Skip to content
Threat Feed

September 2026 (30)

high advisory

SSRF Vulnerability in Nango via Configuration Interpolation

Nango versions through 0.70.4 are vulnerable to Server-Side Request Forgery due to improper validation of user-supplied configuration values in token and proxy URL templates.

Nango webserver ssrf cloud
1t 1c
high advisory

Authorization Bypass in cc-connect via Interactive Card Callbacks

The cc-connect application through version 1.5.0 contains an authorization bypass vulnerability in the onCardAction handler, allowing unprivileged users to execute unauthorized agent commands.

cc-connect vulnerability authorization-bypass cloud
2t 1c
high advisory

Authentication Bypass Vulnerability in GoAdmin

GoAdmin versions through 1.2.26 are vulnerable to an authentication bypass where attackers can manipulate URL pathing to access restricted administrative endpoints.

GoAdmin
1t 1c
high advisory

Authentication Bypass in OpenNHP via Attestation Verification Manipulation

OpenNHP versions up to 1.0.2 contain an authentication bypass vulnerability allowing attackers to force the use of a fallback attestation verifier via malicious input.

OpenNHP authentication-bypass attestation security-flaw
1t 1c
high advisory

Path Traversal in Uber Kraken

Uber Kraken versions 0.1.29 and earlier contain a path traversal vulnerability in the /tags/{tag} endpoint, allowing unauthenticated attackers to read arbitrary files from the filesystem.

Kraken path-traversal vulnerability webserver
1r 1t 1c
high advisory

Insufficient Validation in Coze Studio Workflow SQL Nodes

Coze Studio versions up to 0.5.1 contain an input validation vulnerability in workflow SQL customization nodes allowing authenticated attackers to bypass workspace isolation and execute unauthorized SQL queries.

Coze Studio web-vulnerability sql-injection multi-tenancy cve-2026-92788
1t 1c
high advisory

Remote Code Execution and DoS in Angel via Kryo Deserialization

Angel versions 3.3.0 and earlier are vulnerable to a deserialization flaw allowing unauthenticated remote attackers to trigger arbitrary code execution or denial-of-service via the master RPC endpoint.

1c
high advisory

Cross-Site Scripting via @refinedev/inferencer

The @refinedev/inferencer package versions through 7.0.0 are vulnerable to an injection attack where malicious JSON property names are improperly escaped during JSX code generation, leading to arbitrary JavaScript execution in the developer's browser.

inferencer
1t 1c
high advisory

Authorization Bypass in Yeti RBAC API

Yeti versions 2.11.0 and earlier contain an authorization vulnerability in the DELETE /api/v2/rbac/{id} endpoint that allows unauthorized users to delete access control relationships, causing permanent lockout of legitimate object owners.

Yeti
1r 1t 1c
high advisory

Authorization Bypass in Chroma via Tenant Isolation Failure

Chroma versions 1.5.9 and earlier are vulnerable to an authorization bypass allowing authenticated users to access, modify, and delete cross-tenant data by manipulating collection identifiers.

Chroma vulnerability authorization-bypass
1t 1c
high advisory

KnowStreaming RBAC Bypass Vulnerability

KnowStreaming versions 3.4.1 and earlier contain an improper access control vulnerability in REST API endpoints that allows authenticated users to perform unauthorized privilege escalation.

KnowStreaming
1r 1t 1c
high advisory

Prototype Pollution in Builder.io Gen2 SDKs

Builder.io Gen2 SDKs are vulnerable to prototype pollution in the deep-set helper function, allowing attackers to manipulate Object.prototype via unvalidated content block bindings.

Gen2 SDKs +1 vulnerability web-application javascript
1c
high advisory

Authentication Bypass in Trigger.dev via GitHub App Installation Binding

Trigger.dev versions before 4.6.0 contain an authentication bypass vulnerability allowing attackers to hijack GitHub App installations and gain unauthorized repository access by manipulating state cookies and installation identifiers.

Trigger.dev authentication-bypass github-integration cloud-native
1t 1c
high advisory

Authorization Bypass in Leantime HTMX Plugin Installation

Leantime versions prior to 3.9.6 contain an authorization bypass vulnerability in the HTMX plugin installation endpoint, allowing low-privileged authenticated users to deploy arbitrary plugins.

Leantime
1r 1c
high advisory

Authorization Bypass in Rundeck Project Archive Import

Rundeck versions through 6.2.1 contain an authorization vulnerability in the project archive import endpoint allowing low-privileged users to overwrite sensitive project configuration files.

Rundeck
1t 1c
high advisory

Authorization Bypass in Pelican Panel via Livewire State Manipulation

Pelican Panel versions before 1.0.0-beta35 fail to enforce server-side write permissions, allowing attackers with read-only access to achieve arbitrary command execution via manipulated Livewire state updates.

Pelican Panel web-vulnerability authorization-bypass cve-2026-92762
2t 1c
high advisory

Authorization Bypass in PatrowlManager API

PatrowlManager versions up to 1.8.4 contain an authorization bypass vulnerability in events and alerts API endpoints, allowing authenticated attackers to modify or delete data across different user contexts.

PatrowlManager
1t 1c
high advisory

Authorization Bypass in metasfresh DocumentAttachmentsRestController and CommentsRestController

Authenticated attackers can exploit improper record-level authorization checks in metasfresh ERP to perform unauthorized read, write, and delete operations on attachments and comments.

metasfresh ERP web-application-vulnerability authorization-bypass erp
1t
high advisory

CVE-2026-92749 - Insecure Session Signing Secret Generation in SafeLine

SafeLine versions up to 9.4.1 are vulnerable to unauthorized administrative access due to the derivation of session-signing secrets using a weak time-seeded PRNG.

SafeLine web-application-firewall cryptographic-vulnerability privilege-escalation
2t
high advisory

Path Traversal in BC Security Empire Upload Endpoint

BC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.

Empire vulnerability c2 path-traversal
1t
high threat

Cisco Security Updates - September 2026

Roundup of Cisco security advisories published in September 2026.

roundup
33c updated
critical advisory

JWT Authentication Bypass in Feast

Feast versions 0.66.0 and earlier fail to verify JWT signatures, allowing attackers to bypass RBAC and gain unauthorized read and write access.

Feast
1t
high advisory

SSRF Vulnerability in Quickwit SQS File Source

Quickwit versions through 0.9.0 contain a Server-Side Request Forgery vulnerability allowing unauthenticated attackers to perform internal network scanning and service fingerprinting via the create-source API.

Quickwit ssrf vulnerability web-application
1t 1c
high advisory

Nuclei Template Signature Verification Bypass

Nuclei versions before 3.11.1 are vulnerable to template signature bypass due to reliance on file modification timestamps for cache validation, allowing attackers to inject malicious templates.

Nuclei
1t 1c
high advisory

Arbitrary File Write in Scirius PCAP Filestore Upload

Scirius versions 3.8.0 and earlier are vulnerable to an arbitrary file write attack via the PCAP filestore upload endpoint, allowing authenticated users to perform path traversal to write files to arbitrary locations.

Scirius arbitrary-file-write path-traversal web-application
1r 1t 1c
high advisory

IDOR Vulnerability in SIMAC MyPHR

SIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.

MyPHR idor web-vulnerability vulnerability cve-2026-47094
2t 1c
high advisory

Unauthenticated Form Submission Exfiltration in TDuck

TDuck survey form through version 5.3 contains a vulnerability allowing authenticated attackers to attach unauthorized webhooks to arbitrary forms for data exfiltration.

TDuck
1t 1c
low advisory

BIND 9 Denial of Service via Malformed DNS64 Response

A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.

BIND +5 denial-of-service network-infrastructure vulnerability dns infrastructure
1t 1c
critical advisory

Authentication Bypass in Kubero Notifications API

Kubero versions 3.1.1 and earlier contain an authentication bypass vulnerability in the notifications API, allowing unauthenticated attackers to exfiltrate webhook secrets and manipulate pipeline alerting configurations.

Kubero
1t 1c
critical advisory

CVE-2026-92717 Authentication Bypass in Covenant

Covenant versions 0.6 and earlier contain an authentication bypass vulnerability allowing unauthenticated remote actors to gain full operator API access via the CovenantHub SignalR hub.

Covenant authentication-bypass c2-infrastructure cve-2026-92717
1t 1c