Tag: info-disclosure
All entries tagged info-disclosure.
- OpenAI-attributed agents ran 16,500+ scans against a UN statistics API over two months, using public URL-scanner services as blind proxies and double-URL-encoding to bypass a GET/POST access restriction
- A sideloaded AppX package turns a Microsoft-signed web host into an OAuth token thief: the login dialog is genuine, the MFA is genuine, and the tokens go to the attacker
- Microsoft's public Entra ID password-reset portal leaks account existence, registered MFA methods and likely-admin status to any unauthenticated visitor
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)
- Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter; patched for legacy Player V2 after months of no vendor response, 630+ exposed instances found by the discoverer
- Truffle Security re-tested 10,616 leaked AWS key pairs and 88% still authenticate; 768 of them give full control of a company account, and none of the measured leak surfaces is the current working tree
- Three misp-stix flaws put the CTI pipeline itself in scope: a crafted STIX document can set its own MISP distribution and sharing fields, kill a long-running importer, or bleed data into the next event
- CVE-2026-19586, TP-Link Omada gateways: attacker-supplied data during OpenVPN connection establishment reaches command execution before authentication completes (CVSS 4.0 9.3)
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, administrators included
- CVE-2026-64849, MLflow: the SSRF guard resolves the webhook host and then throws the answer away, so one redirect turns an unauthenticated tracking server into a reader of its own cloud credentials
- NHS Blood and Transplant sent organ-offer messages naming recipients over an unencrypted pager network, and because pager broadcasts leave no receiver log, it cannot scope who received them
- CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy
- Belgium's eID signing extension handed any web page the card, the PIN and a drive-by RCE, an eIDAS Qualified Trust Service Provider's browser bridge that never checked the caller's origin
- NatJack, sharing a NAT table is a trust relationship nobody declared: five named primitives against NAT state, of which only the downstream TCP hijack got a CVE on each platform
- 22 CVEs in Tobit TeamDavid, a DACH-region self-hosted Microsoft 365 alternative: an unauthenticated heap leak hands over stored mailbox passwords, and the vendor stopped responding
- Flowise ships three new CVEs into a sunset, an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them
- CVE-2026-54363 and five siblings, Gladinet CentreStack: one cryptographic key shared across every installation forges a domain-administrator token, completing an unauthenticated RCE chain
- CVE-2026-48449, Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
- CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
- CVE-2026-66066, Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)
- HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- CVE-2013-4786, 24,650 internet-exposed BMCs hand a crackable password hash to any unauthenticated caller, and Lava found ransom notes on live management interfaces
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it
- CVE-2025-15467, Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)
- CVE-2025-68686, FortiOS SSL-VPN: the fix for the symlink-persistence technique is itself bypassable, and CISA now lists it as exploited
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection
- CISA ICS batch (14 Jul): Rockwell 1715-AENTR unauthenticated debug-port takeover (CVE-2026-10577, CVSS 10.0, fixed in firmware 3.011) and a Swiss-vendor ABB T-MAC Plus auth chain (CVSS 9.9)
- Open WebUI's six broken-access-control CVEs are one recurring authorization-architecture defect, not six isolated bugs
- CVE-2026-59509, cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)
- CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC
- Unit 42: cloud-bucket hijacking via global-namespace reuse silently redirects log and replication streams
- "Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)
- CVE-2026-4020, Gravity SMTP WordPress plugin: unauthenticated config-dump of email-connector credentials, mass-exploited
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform
- Varonis "SearchLeak" (CVE-2026-42824): one-click M365 Copilot data exfiltration, now patched
- June 2026 Patch Tuesday: four CVSS ≥ 9.1 criticals, Windows kernel TCP/IP RCE, Nuance PowerScribe, Azure Stack Edge, Exchange Online
- CVE-2026-49200 / CVE-2026-49201, Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch
- CVE-2024-21182, Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- ChatGPhish: Permiso Security documents ChatGPT Markdown renderer trusting third-party image URLs and links, used for IP exfiltration and phishing via legitimate chatgpt.com
- CVE-2026-4868 (+ five further CVEs), GitLab 19.0.1 / 18.11.4 / 18.10.7 patch release: Duo AI identity impersonation, unauthenticated project enumeration
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
- CVE-2026-9642, Delta Electronics DIAView SCADA: incomplete fix for prior unauthenticated remote database access (CVE-2025-62582)
- CVE-2026-9312, GitHub Enterprise Server (< 3.22): unauthenticated SSRF via upload-endpoint path traversal exposes internal services and credentials
- Ghost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
- CVE-2026-26980, Ghost CMS Content API: unauthenticated blind SQL injection in the slug filter, actively exploited
- Large-scale ClickFix campaign mass-compromises self-hosted Ghost CMS sites via CVE-2026-26980
- BigBlueButton bbb-web < 3.0.21 / < 3.0.23, three flaws in EU education and government virtual-classroom platform: weak session-token randomness, API checksum bypass, SSRF
- CVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox escape → credential leak → privilege escalation → file disclosure