2026-07-05NOTABLEcve-search patches a pre-auth flaw that reads admin credential hashes via /fetch_cve_data
cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes
cve · CVE-2026-59509
Coverage
1
first 2026-07-05 → last 2026-07-05
Latest activity
2026-07-05
cve-search patches a pre-auth flaw that reads admin credential hashes via /fetch_cve_data
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology · regions: europe
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-59509, newest first. Check the date before acting on an older one.
- Inventory cve-search deployments and upgrade to v6.0.1 or later; the fix allowlists the retrieve/column parameters and enforces pagination bounds on /fetch_cve_data.2026-07-05CVE-2026-59509
- Until upgraded, confirm the cve-search web/API component is not reachable from untrusted networks (reverse-proxy / firewall ACLs on the Flask listener) and, if internet-facing, treat exposure as urgent.2026-07-05CVE-2026-59509
- If /fetch_cve_data may have been reached with non-default collection/column/regex parameters, rotate all cve-search admin credentials, mgmt_users hashes exposed to read enable offline cracking.2026-07-05CVE-2026-59509
Defender insights
What each entry about CVE-2026-59509 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Credential AccessUnsecured Credentials
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql · ATT&CK page ↗
Entries about cve-search unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (1)
Where this entity is cited
Source distribution
- cve.threatint.eu1 (50%)
- github.com1 (50%)