---
schema: 1
kind: vulnerability
title: "CVE-2026-59509 — cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)"
headline: "cve-search patches a pre-auth flaw that reads admin credential hashes via /fetch_cve_data"
summary: >
  An unauthenticated improper-input-validation flaw (CVE-2026-59509, CVSS 4.0 9.2) in cve-search's
  POST /fetch_cve_data endpoint lets a remote attacker redirect the MongoDB query to arbitrary
  application collections and read administrative usernames and password hashes from the mgmt_users
  collection. cve-search v4.0 through v6.0.0 are affected; the fix landed in v6.0.1. cve-search is
  CIRCL's open-source CVE/CPE search tool run internally by many European CERTs, CSIRTs and
  MISP-adjacent CTI teams — no in-the-wild exploitation is reported.
discovered_at: "2026-07-05T18:16:00Z"
event_date: "2026-07-05"
run_id: 2026-07-05T1809Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, pre-auth, info-disclosure, sqli, patch-available]
regions: [europe]
sectors: [public-sector, technology]
entities: []
cves:
  - id: CVE-2026-59509
    cvss: "9.2"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "v4.0 – v6.0.0"
    fixed: "v6.0.1"
sources:
  - url: "https://github.com/cve-search/cve-search/pull/1218"
    publisher: "cve-search project (GitHub PR #1218 — fix)"
    date: "2026-06-22"
    role: primary
  - url: "https://cve.threatint.eu/CVE/CVE-2026-59509"
    publisher: "ThreatInt.eu (CVE aggregator)"
    date: "2026-07-05"
    role: corroborating
closed_sources: []
evidence:
  - quote: "An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose administrative usernames and password hashes from the mgmt_users collection, enabling offline password cracking and potential administrative account compromise."
    publisher: "ThreatInt.eu (CVE aggregator)"
  - quote: "fix(web): add server-side validations for /fetch_cve_data inputs"
    publisher: "cve-search project (GitHub PR #1218 — fix)"
verification: multi-source
sourcing_note: >
  First-party disclosure and fix by the cve-search project itself (GitHub issue #1217 / PR #1218,
  merged 2026-06-22, released in v6.0.1), corroborated by the CIRCL-assigned CVE record on an
  independent aggregator; CVE identifier and CVSS re-verified against the NVD entry (not cited — NVD
  per-CVE pages are verification-only). No confirmed in-the-wild exploitation and EPSS not published
  as of this run — confidence held to medium accordingly.
confidence: medium
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "Inventory cve-search deployments and upgrade to v6.0.1 or later; the fix allowlists the retrieve/column parameters and enforces pagination bounds on /fetch_cve_data."
  - "Until upgraded, confirm the cve-search web/API component is not reachable from untrusted networks (reverse-proxy / firewall ACLs on the Flask listener) and, if internet-facing, treat exposure as urgent."
  - "If /fetch_cve_data may have been reached with non-default collection/column/regex parameters, rotate all cve-search admin credentials — mgmt_users hashes exposed to read enable offline cracking."
migrated_from: null
---

CVE-2026-59509 is an unauthenticated improper-input-validation flaw (CWE-20, CVSS 4.0 9.2, vector `AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N`) in the `POST /fetch_cve_data` endpoint of **cve-search**, the open-source CVE/CPE aggregation and search tool maintained by CIRCL (Luxembourg's CSIRT) and widely run internally by European CERTs, CSIRTs and MISP-adjacent CTI teams. The handler trusted attacker-controlled request parameters to select the target MongoDB collection, the projected fields, and the regex filters rather than restricting queries to the CVE collection, so a remote unauthenticated caller could redirect the query to arbitrary application collections — including `mgmt_users` — and read administrative usernames and password hashes, enabling offline cracking and admin-account takeover of the instance ([CIRCL/NVD, 2026-07-05](https://cve.threatint.eu/CVE/CVE-2026-59509)). Versions v4.0 through v6.0.0 are affected; the project's own fix (`fix(web): add server-side validations for /fetch_cve_data inputs`) was merged 2026-06-22 and shipped in v6.0.1, adding a CVE-only collection restriction, an allowlist for DataTables column fields, and enforced pagination bounds — all invalid requests now return HTTP 400 ([cve-search project, GitHub PR #1218](https://github.com/cve-search/cve-search/pull/1218)). No in-the-wild exploitation has been reported by either source and EPSS is not yet published, consistent with a same-day CVE assignment on an already-merged fix.

**Defender takeaway:** This is a defensive-tooling supply-chain exposure aimed squarely at the CTI stack this constituency itself operates, not a mass-internet edge bug — cve-search is meant to sit on internal networks, so the operational priority is confirming that assumption holds. Hunt for `POST /fetch_cve_data` requests carrying non-default `retrieve`/column/regex parameters in the Flask web component's access logs (T1190 Exploit Public-Facing Application), and treat any instance reachable from untrusted networks as an immediate upgrade-and-credential-rotation case (T1552 Unsecured Credentials via the exposed `mgmt_users` hashes). Upgrading past v6.0.0 to v6.0.1 is the durable fix; a reverse-proxy rule constraining `/fetch_cve_data` to CVE-collection requests is an interim mitigation where an immediate upgrade is not possible.
