Tag

#Unauthenticated Attack

articleHIGH 7.5

CVE-2026-15561: Unauthenticated Denial of Service in Red Hat JBoss Enterprise Application Platform

A vulnerability in the undertow HTTP/1.1 chunked-transfer decoder of Red Hat JBoss Enterprise Application Platform (EAP) 7.4 ELS on RHEL 7 allows an unauthenticated attacker to cause a Denial of Service (DoS) by driving the JVM to an OutOfMemory error. The vulnerability has a CVSS score of 7.5 and is not currently being actively exploited. Affected products include various packages such as eap7-activemq-artemis, eap7-glassfish-jsf, and eap7-jackson-annotations, among others. Immediate patching is recommended to prevent potential DoS attacks.

1 source
blogHIGH 8.2

Understanding and Defending Against CVE-2026-16268: Unauthenticated Request Forgery in Newsletters WordPress Plugin

CVE-2026-16268 is a vulnerability in the Newsletters WordPress plugin that allows unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts. This vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. It is not actively exploited in the wild. Understanding this vulnerability is crucial for defenders to protect their WordPress installations.

1 source
newsHIGH 8.2

CVE-2026-14829: Unauthenticated License Deactivation in Checkimate WordPress Plugin

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 has a vulnerability allowing unauthenticated attackers to deactivate the plugin's premium licensing state and erase the stored license key. This vulnerability has a CVSS score of 8.2, indicating high severity. Affected users should update to a patched version.

1 source
articleHIGH 8.1

CVE-2026-39923: Flarum Password Reset Token Expiry Bypass Vulnerability

A critical vulnerability (CVE-2026-39923, CVSS 8.1) in Flarum, a popular discussion platform, allows unauthenticated attackers to bypass the 24-hour password reset token expiry, potentially leading to unauthorized account takeovers. The vulnerability affects Flarum versions prior to 1.8.16. Organizations using Flarum should immediately upgrade to version 1.8.16 or later to mitigate this risk. Failure to do so may result in compromised user accounts and potential lateral movement within the network.

1 source
articleCRITICAL 9.1

Critical Vulnerability in Clawvet Self-Hosted API Server: CVE-2026-62241

A critical vulnerability (CVE-2026-62241, CVSS 9.1) exists in the Clawvet self-hosted API server (apps/api) before version 0.7.5. The vulnerability allows a remote unauthenticated attacker to harvest user IDs, forge a valid session cookie, and obtain sensitive user information. The vulnerability has not been actively exploited but poses a significant risk due to its severity and the potential for exploitation. Immediate patching to version 0.7.5 or later is strongly recommended.

1 source
newsHIGH 8.6

CVE-2026-61436: PraisonAI Webhook Signature Verification Bypass

A vulnerability in PraisonAI before version 4.6.78 allows unauthenticated attackers to forge message.received events by sending crafted JSON payloads to the webhook endpoint, potentially invoking configured agents with arbitrary sender addresses and message content. This vulnerability has a CVSS score of 8.6 and is classified as HIGH severity.

1 source
articleCRITICAL 9.8

Critical Command Injection Vulnerability in Sustainable Irrigation Platform (SIP)

A critical command injection vulnerability (CVE-2026-58479) has been discovered in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The vulnerability, located in the optional cli_control plugin, allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands. This can be achieved by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor'. The vulnerability has a CVSS score of 9.8 and is considered critical.

1 source