Skip to content
Threat Feed

Tag

API

26 briefs RSS
high advisory

Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle

A vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.

npm/@budibase/server <= 3.38.1 +1 budibase vulnerability file-read information-disclosure cloud mongodb api web-vulnerability +1
2r 6t 2i
critical advisory

Authentication Bypass in kin-openapi Due to Default NoopAuthenticationFunc

An authentication bypass vulnerability (CWE-287) exists in the `openapi3filter.ValidationHandler` component of the `getkin/kin-openapi` library (versions <= v0.143.0), where the `ValidationHandler.Load()` method silently defaults to a `NoopAuthenticationFunc` when an explicit function is not provided, allowing unauthenticated remote attackers to bypass OpenAPI security requirements and access protected endpoints in Go services.

kin-openapi authentication-bypass api golang library-vulnerability cwe-287
1t
critical advisory

CVE-2026-63764: Server-Side Request Forgery in lmdeploy OpenAI-Compatible API Server

An unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-63764, exists in lmdeploy's OpenAI-compatible API server, allowing attackers to access internal services and cloud metadata by submitting a crafted image_url that redirects to internal targets.

lmdeploy's OpenAI-compatible API server server-side-request-forgery ssrf vulnerability api cloud-security
1r 1t 1c
critical advisory

Gitea Incomplete SSRF Protection in Webhook and Migration Allow-list

An incomplete Server-Side Request Forgery (SSRF) protection in Gitea versions prior to 1.26.3 allows authenticated users to bypass the allow-list in webhook delivery and repository migrations, enabling internal network probing and data exfiltration from sensitive services like cloud metadata endpoints.

Gitea ssrf web-application data-exfiltration vulnerability github authorization-bypass information-disclosure api +5
4t 1c 1i
high advisory

Grav API Plugin Vulnerability Exposes JWT Access Tokens via URL Parameter

The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.0-rc.16 is vulnerable to sensitive information exposure, accepting JWT access tokens via the '?token=' URL query parameter, causing these tokens to be logged in web server access logs, browser history, and potentially leaked through Referer headers, proxy, or CDN logs, which allows an attacker to gain unauthorized API access, read configuration and user data, create new admin accounts, modify system settings, and delete pages.

Grav API plugin +1 vulnerability web api jwt information-exposure grav
1r 6t 1c
critical advisory

Clawvet API Server Hard-Coded JWT Secret Vulnerability (CVE-2026-62241)

A critical vulnerability exists in the clawvet self-hosted API server (apps/api) before version 0.7.5 due to a hard-coded fallback JWT secret ('clawvet-dev-secret-change-me') shipped in the default .env.example, allowing an unauthenticated remote attacker to harvest user IDs, forge session cookies, and retrieve sensitive user information including email address, subscription plan, and API key via the /api/v1/auth/me endpoint.

clawvet self-hosted API server vulnerability CVE-2026-62241 JWT API hardcoded-secret
3t 1c 1i
high advisory

Unauthenticated Access to @andrea9293/mcp-documentation-server Web UI/API

The `@andrea9293/mcp-documentation-server` version 1.13.0 defaults to binding its Web UI/API to all network interfaces (0.0.0.0:3080) and lacks authentication for its document-management endpoints, enabling any network-reachable attacker to perform unauthorized operations such as reading, searching, adding, and deleting documents, potentially corrupting the user's knowledge base.

@andrea9293/mcp-documentation-server vulnerability web api node.js default-misconfiguration unauthenticated-access
1r 4t
critical advisory

CVE-2026-61451: Unauthenticated Account Takeover in Grav API Plugin via Password Reset Vulnerability

An unauthenticated attacker can exploit CVE-2026-61451 in Grav API plugin versions prior to 1.0.4, leveraging improper URL validation in the password reset functionality to specify an arbitrary host in the reset link, thereby disclosing valid reset tokens to an attacker-controlled server and enabling full account takeover.

Grav API plugin web-vulnerability account-takeover password-reset grav api
1r 3t 1c
high advisory

Kimai REST API Two-Factor Authentication Bypass Vulnerability

A critical vulnerability, CVE-2026-52827, in Kimai versions prior to 2.59.0 allows an attacker who has compromised a user's password to bypass Two-Factor Authentication (TOTP) for the REST API by intercepting and replaying the `KIMAI_SESSION` cookie obtained after password verification but before TOTP completion, granting full authenticated API access.

Kimai api 2fa-bypass vulnerability web-application
2t
high advisory

CVE-2026-59708: Ghostfolio Unauthenticated Portfolio Data Exposure

An authorization bypass vulnerability (CVE-2026-59708) in Ghostfolio's GET /api/v1/public/:accessId/portfolio endpoint allows unauthenticated attackers with a private access ID to retrieve sensitive financial portfolio data, including holdings and performance metrics, due to missing `granteeUserId` filtering validation.

ghostfolio <= 3.6.0 vulnerability api authorization-bypass data-exposure webserver
3t 1c
high advisory

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

An SSRF protection bypass vulnerability, CVE-2026-33655, in the QuantumNous new-api, affecting versions prior to v0.12.0-alpha.1, allows authenticated users to send requests to internal HTTP services by configuring notification URLs with unresolved hostnames, leading to potential sensitive internal data exposure through timing, errors, or response-dependent behavior.

new-api ssrf api vulnerability bypass web-application
2t
high advisory

OpenRemote Cross-Realm User Information Disclosure (CVE-2026-54641)

A high-severity vulnerability (CVE-2026-54641) in OpenRemote's `UserResourceImpl.java` allows a realm administrator in a multi-tenant deployment to perform cross-realm user enumeration and privilege-level reconnaissance by reading sensitive user information (profile, client roles, and realm roles) from any other realm, including the master realm, due to missing authorization checks in specific REST API endpoints.

openremote-manager OpenRemote Vulnerability API Information Disclosure Access Control Multi-tenant
1r 2t
high advisory

Mautic 7 API v2 Authorization Bypass (CVE-2026-9808)

An authorization bypass vulnerability (CVE-2026-9808) exists in Mautic 7 API v2 endpoints, where owner-scope restrictions are not properly enforced, allowing low-privilege authenticated API users to access or modify resources belonging to other users, bypassing ownership controls and impacting data confidentiality and integrity.

Mautic Core mautic authorization-bypass api web-application
2t 1c
high advisory

Kirby CMS Missing Authorization Vulnerability in /api/site/find (CVE-2026-54005)

An authenticated user can exploit CVE-2026-54005, a high-severity missing authorization vulnerability in Kirby CMS versions <= 4.9.3 and from 5.0.0-alpha.1 to <= 5.4.3, via the `/api/site/find` REST API route to bypass `pages.access` permissions and retrieve sensitive content and metadata from unauthorized pages.

composer/getkirby/cms +1 cms vulnerability kirby information-disclosure api webserver
2r 3t
critical advisory

PraisonAI Call Server Unauthenticated Agent Control API

PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not configured, allowing attackers to list, inspect, invoke, and unregister agents due to a fail-open authentication default and a default binding to `0.0.0.0`, as tracked by CVE-2026-47396.

PraisonAI unauthenticated-access api
2r 2t
high advisory

GitHub CLI Incorrectly Includes Authorization Header in API Requests

GitHub CLI versions 2.92.0 and earlier incorrectly include authorization headers in API requests to TUF repository mirrors and external hosts when using the `gh attestation`, `gh release verify`, and `gh release verify-asset` commands, potentially exposing sensitive tokens.

cli/cli/v2 +1 github cli token leakage api
2r 1t 3i
medium advisory

Entra ID OAuth User Impersonation to Microsoft Graph

This rule detects potential session hijacking or token replay in Microsoft Entra ID, identifying cases where a user signs in and subsequently accesses Microsoft Graph from a different IP address using the same session ID, which may indicate a successful OAuth phishing attack, session hijacking, or token replay attack.

Entra ID +1 cloud identity api azure oauth session hijacking
2r 2t
critical advisory

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Secure Workload versions 3.9 and prior, versions prior to 3.10.8.3, and versions prior to 4.0.3.17 are vulnerable to unauthorized API access, requiring an urgent update.

Secure Workload cisco vulnerability api
1r
medium advisory

Microsoft Graph Multi-Category Reconnaissance Burst

The rule detects Microsoft Graph activity from delegated user tokens where a single user session and source IP rapidly touches multiple high-value Graph paths indicative of reconnaissance, suggesting a broad enumeration playbook.

Microsoft Graph cloud identity api azure microsoft-entra-id microsoft-graph threat-detection discovery
2r 2t
high advisory

PraisonAI Legacy API Server Authentication Bypass (CVE-2026-44338)

PraisonAI ships a legacy Flask API server with authentication disabled by default, allowing any reachable caller to access `/agents` and trigger the configured `agents.yaml` workflow through `/chat` without providing a token (CVE-2026-44338).

PraisonAI authentication bypass API CVE-2026-44338
2r 1t 1c
critical advisory

OpenViking Authentication Bypass Vulnerability (CVE-2026-40525)

OpenViking versions prior to commit c7bb167 are vulnerable to an authentication bypass that allows remote attackers to invoke privileged bot-control functionality without authentication when the api_key configuration is unset or empty, potentially leading to unauthorized access to downstream systems and data.

CVE-2026-40525 authentication-bypass openviking api
2r 1t 1c
critical advisory

Paperclip Cross-Tenant Agent API Key IDOR Vulnerability

A Paperclip API vulnerability allows a board user from one company to create, list, and revoke agent API keys in another company, leading to full cross-tenant compromise due to insufficient authorization checks on `/agents/:id/keys` routes.

idor cross-tenant api paperclip privilege-escalation
3r 5t
high threat

Kimsuky Malware Using Dropbox API for Command and Control

Kimsuky is using malware that leverages the Dropbox API for command and control, enabling file exfiltration and remote code execution.

Kimsuky +4 dropbox api command-and-control exfiltration
2r 2t
high advisory

Decidim API Unauthorized Access via CVE-2026-40870

CVE-2026-40870 allows unauthenticated access to commentable resources in Decidim platforms prior to versions 0.30.5 and 0.31.1 due to missing permission checks on the publicly accessible `/api` endpoint, potentially exposing sensitive data.

Decidim cve-2026-40870 api unauthorized-access
2r 1t 1c
high advisory

Snipe-IT Privilege Escalation via API Permissions Assignment (CVE-2026-44832)

An authenticated user with limited 'users.edit' permissions can escalate their privileges to 'admin' in Snipe-IT versions before 8.4.1 by manipulating the permissions array in a PATCH request to the API, as tracked by CVE-2026-44832.

Snipe-IT privilege-escalation web-application api
2r 1t
medium advisory

Okta API Token Revoked

Detection of Okta API token revocation events, indicating potential unauthorized access or compromise.

Okta api token revocation identity
2r 1t