{"resultsPerPage":28,"startIndex":0,"totalResults":28,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-21T14:04:50.916","vulnerabilities":[{"cve":{"id":"CVE-2025-23367","sourceIdentifier":"secalert@redhat.com","published":"2025-01-30T15:15:18.610","lastModified":"2026-08-21T10:16:36.507","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. \nThe vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action."},{"lang":"es","value":"Se encontró una falla en el proveedor Wildfly Server Role Based Access Control (RBAC). Cuando la autorización para controlar las operaciones de administración se asegura mediante el proveedor de control de acceso basado en roles, un usuario sin los privilegios requeridos puede suspender o reanudar el servidor. Se supone que un usuario con un rol de Monitor o Auditor solo tiene permisos de acceso de lectura y no debería poder suspender el servidor. La vulnerabilidad se debe a que los controladores de Suspensión y Reanudación no realizan comprobaciones de autorización para validar si el usuario actual tiene los permisos requeridos para continuar con la acción."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://github.com/wildfly/wildfly-core","packageName":"wildfly-core","versions":[{"version":"0","lessThan":"27.0.1.Final","versionType":"semver","status":"affected"},{"version":"28.0.0.Beta1","lessThan":"28.0.0.Beta2","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty-transport-native-epoll","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-wildfly","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:7.4.21-3.GA_29548_redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty-transport-native-epoll","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-wildfly","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:7.4.21-3.GA_29548_redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty-transport-native-epoll","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:4.1.119-1.Final_redhat_00004.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-wildfly","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8","cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"],"versions":[{"version":"0:7.4.21-3.GA_29548_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-apache-commons-io","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:2.16.1-1.redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-bouncycastle","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:1.80.0-1.redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-eap-product-conf-parent","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:800.7.0-2.GA_redhat_00002.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-hibernate","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:6.2.35-1.Final_redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-ironjacamar","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:3.0.13-1.Final_redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-jakarta-enterprise-concurrent","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:3.0.1-1.redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-jsf-impl","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:4.0.11-1.redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-reactive-streams","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:1.0.4-3.redhat_00004.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-reactivex-rxjava","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:3.1.10-1.redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-weld-core","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:5.1.5-1.Final_redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-wildfly","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:8.0.7-3.GA_redhat_00004.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-wildfly-elytron","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"],"versions":[{"version":"0:2.2.9-1.Final_redhat_00001.1.el8eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-apache-commons-io","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:2.16.1-1.redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-bouncycastle","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:1.80.0-1.redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-eap-product-conf-parent","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:800.7.0-2.GA_redhat_00002.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-hibernate","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:6.2.35-1.Final_redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-ironjacamar","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:3.0.13-1.Final_redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-jakarta-enterprise-concurrent","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:3.0.1-1.redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-jsf-impl","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:4.0.11-1.redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-reactive-streams","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:1.0.4-3.redhat_00004.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-reactivex-rxjava","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:3.1.10-1.redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-weld-core","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:5.1.5-1.Final_redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-wildfly","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:8.0.7-3.GA_redhat_00004.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap8-wildfly-elytron","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9"],"versions":[{"version":"0:2.2.9-1.Final_redhat_00001.1.el9eap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Build of Keycloak","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:build_keycloak:"]},{"vendor":"Red Hat","product":"Red Hat Data Grid 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_data_grid:8"]},{"vendor":"Red Hat","product":"Red Hat Fuse 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_fuse:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Data Grid 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_data_grid:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform Expansion Pack","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jbosseapxp"]},{"vendor":"Red Hat","product":"Red Hat Process Automation 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:jboss_enterprise_bpms_platform:7"]},{"vendor":"Red Hat","product":"Red Hat Single Sign-On 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"wildfly-server","cpes":["cpe:/a:redhat:red_hat_single_sign_on:7"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-30T14:54:55.951787Z","id":"CVE-2025-23367","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"7.4","versionEndExcluding":"7.4.21","matchCriteriaId":"48709188-93C0-4992-B09F-CEC7A16EABEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.7","matchCriteriaId":"E3FD087B-337E-4069-AF83-9BD2938EB81B"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:*","versionEndExcluding":"27.0.1","matchCriteriaId":"AB978A4B-0A80-4E19-B910-CF9DA9A1E892"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:wildfly:28.0.0:beta1:*:*:*:*:*:*","matchCriteriaId":"39D9F54C-D628-4CD5-81A6-2F003A00EDF3"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3465","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3467","source":"secalert@redhat.com","tags":["Issue Tracking"]},{"url":"https://access.redhat.com/errata/RHSA-2025:3989","source":"secalert@redhat.com","tags":["Issue Tracking"]},{"url":"https://access.redhat.com/errata/RHSA-2025:3990","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3992","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-23367","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2337620","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://github.com/advisories/GHSA-qr6x-62gq-4ccp","source":"secalert@redhat.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-60074","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-07-30T14:17:02.587","lastModified":"2026-08-21T09:16:39.010","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check.\n\nThe parse regexes capture year, month and day with the `\\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction.\n\nAny caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Date-Manip","modules":["Date::Manip"],"programFiles":["lib/Date/Manip/Base.pm","lib/Date/Manip/Date.pm"],"programRoutines":[{"name":"Date::Manip::Base::check"},{"name":"Date::Manip::Date::_parse_check"},{"name":"Date::Manip::Date::_iso8601_rx"},{"name":"Date::Manip::Date::_other_rx"},{"name":"Date::Manip::Date::parse_format"}],"repo":"https://github.com/SBECK-github/Date-Manip","packageURL":"pkg:cpan/Date-Manip","versions":[{"version":"0","lessThanOrEqual":"6.99","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T17:57:22.582933Z","id":"CVE-2026-60074","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-1289"}]}],"references":[{"url":"https://github.com/SBECK-github/Date-Manip/pull/54","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Base.pm#L602-614","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1536-1539","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/19","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-60075","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-07-30T14:17:02.710","lastModified":"2026-08-21T09:16:39.207","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time.\n\n_parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached through a leading `(?:$atrx|^|\\s+)`. The engine therefore retries the match at every position of an interior whitespace run: at each start position the leading `\\s+` consumes the rest of the run greedily, the time alternation fails because the run holds no digits, and the engine backtracks a space at a time across the run before advancing the start position, which is quadratic in the length of the run. No time need be present in the string for this to happen, only a long run of whitespace, and the parse time rises about fourfold for each doubling of the run: a few kilobytes of whitespace costs seconds of CPU per parse and tens of kilobytes costs minutes.\n\nAny caller that passes an untrusted string of unbounded length to ParseDate(), Date::Manip::Date->parse() or ->parse_time() can be made to spend unbounded CPU in a single parse, a denial of service."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Date-Manip","modules":["Date::Manip"],"programFiles":["lib/Date/Manip/Date.pm"],"programRoutines":[{"name":"Date::Manip::Date::_parse_time"},{"name":"Date::Manip::Date::_other_rx"},{"name":"Date::Manip::Date::parse"},{"name":"Date::Manip::Date::parse_time"},{"name":"Date::Manip::DM6::ParseDate"}],"repo":"https://github.com/SBECK-github/Date-Manip","packageURL":"pkg:cpan/Date-Manip","versions":[{"version":"0","lessThanOrEqual":"6.99","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-31T17:55:49.530428Z","id":"CVE-2026-60075","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-1333"}]}],"references":[{"url":"https://github.com/SBECK-github/Date-Manip/pull/55","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1526","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/SBECK/Date-Manip-6.99/source/lib/Date/Manip/Date.pm#L1811","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/20","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-74940","sourceIdentifier":"security@mozilla.org","published":"2026-08-18T13:17:30.370","lastModified":"2026-08-21T10:47:55.223","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1."}],"affected":[{"source":"security@mozilla.org","affectedData":[{"vendor":"Mozilla","product":"Firefox","versions":[{"version":"115.39","lessThanOrEqual":"115.*","versionType":"rpm","status":"unaffected"},{"version":"140.14","lessThanOrEqual":"140.*","versionType":"rpm","status":"unaffected"},{"version":"153.1","lessThanOrEqual":"153.*","versionType":"rpm","status":"unaffected"},{"version":"154","lessThanOrEqual":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Mozilla","product":"Thunderbird","versions":[{"version":"140.14","lessThanOrEqual":"140.*","versionType":"rpm","status":"unaffected"},{"version":"153.1","lessThanOrEqual":"153.*","versionType":"rpm","status":"unaffected"},{"version":"154","lessThanOrEqual":"*","versionType":"rpm","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"115.39.0","matchCriteriaId":"FD8DBFC4-10A7-41E2-B754-71CC6FEEBB5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"116.0","versionEndExcluding":"140.14.0","matchCriteriaId":"502016C0-F897-4F18-BFC7-301B71D93E4D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionStartIncluding":"141.0","versionEndExcluding":"154.0.0","matchCriteriaId":"5021AD96-5DC2-41D2-A3F4-4F6E8059CA37"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"140.14.0","matchCriteriaId":"4E2EC2AA-23B2-45C9-8594-DF80A0D800A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionStartIncluding":"141.0","versionEndExcluding":"153.1.0","matchCriteriaId":"47206424-A249-46CE-9776-F45A49344204"}]}]}],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2054842","source":"security@mozilla.org","tags":["Permissions Required"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-74/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-75/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-76/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-77/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-78/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-79/","source":"security@mozilla.org","tags":["Vendor Advisory"]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-80/","source":"security@mozilla.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-47359","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.000","lastModified":"2026-08-21T09:16:38.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0) accept unsanitized command options for the backup repository. A malicious operator account can exploit this to inject arbitrary commands that execute on the KVM hypervisor host when any account subsequently performs a backup restore.\n\nThis issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.20.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-50112","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.150","lastModified":"2026-08-21T09:16:38.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SSRF via Metalink Mirror URL Resolution:\n\nAn authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be downloaded through normal APIs.\n\nRCE on KVM hypervisor via NFS, Metalink files with/without Direct Downloads:\n\nAn authenticated CloudStack tenant holding the default User role can execute arbitrary shell commands as root on the KVM hypervisor host that runs other tenants' VMs. This is cross-tenant root on the underlying compute, reachable via the public CloudStack API.\n\n\nWhen a User registers a VM template with directDownload=true and a URL pointing to a .metalink file, the management server fetches the metalink XML and dispatches download to the KVM agent. Inner URLs inside the metalink XML are never re-validated against the scheme allowlist.\n\n\nThese issues affect Apache CloudStack: from 4.14.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.14.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-78"},{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-50222","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.280","lastModified":"2026-08-21T09:16:38.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs.\n\nSeveral userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine, deployVirtualMachine, and updateVirtualMachine, exhibit missing or insufficient access control validation, potentially allowing cross-tenant/cross-account access to userdata resources that belong to other tenants.\n\nThis issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nThe deleteCniConfiguration API, introduced in 4.21.0.0, also exhibits similar behaviour and lacks access validation.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.18.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-59085","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.410","lastModified":"2026-08-21T09:16:38.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests.\n\nThis issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.20.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-59655","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.533","lastModified":"2026-08-21T09:16:38.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers.\n\nThis issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.19.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-59657","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.657","lastModified":"2026-08-21T09:16:38.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database.\n\nThis issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-59780","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.770","lastModified":"2026-08-21T09:16:38.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers.\n\n\n\n\n\n\n\n\n\n\n\nLDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\nThis issue affects Apache CloudStack: from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.2.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-59799","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:38.890","lastModified":"2026-08-21T09:16:38.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow.\n\nThis issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.18.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61397","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.363","lastModified":"2026-08-21T09:16:39.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration.\n\nThis issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.19.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61398","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.480","lastModified":"2026-08-21T09:16:39.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality.\n\nThis issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.15.1.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61399","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.603","lastModified":"2026-08-21T09:16:39.603","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality.\n\nThis issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.20.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-116"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61400","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.717","lastModified":"2026-08-21T09:16:39.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers.\n\nAn authenticated user holding the permissions required to invoke either `getDiagnosticsData` or `runDiagnostics` can achieve arbitrary command execution on the system VM and/or Virtual Router instances, with commands running as root (or as the diagnostics-process user, at minimum). This represents a full compromise of the affected instance and, depending on network segmentation, may provide a foothold for lateral movement within the CloudStack-managed infrastructure, including access to guest network traffic handled by the compromised Virtual Router.\n\n\n\nThe getDiagnosticsData and runDiagnostics APIs are restricted to only Admin role accounts by default.\n\n\nThis issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.14.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61422","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.840","lastModified":"2026-08-21T09:16:39.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality.\n\nWhen registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens before URL validation is performed. However, this does not pose a malicious template or ISO registration risk, as URL validation still occurs prior to the actual download by the Secondary Storage VM.This issue affects Apache CloudStack: in 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-62440","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:39.963","lastModified":"2026-08-21T09:16:39.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes.\n\nThis issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-63046","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.083","lastModified":"2026-08-21T09:16:40.083","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell\ncommands via ExcuteLinux.exeCmd() with no filtering or whitelist\nvalidation. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1]/[2] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12151 .\n\n[2]  https://github.com/apache/inlong/pull/12155 ."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache InLong","defaultStatus":"unaffected","versions":[{"version":"2.0.0","lessThan":"2.4.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://lists.apache.org/thread/2pgz70rz9ozfm7vm5c33po3yyspq846y","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-65613","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.207","lastModified":"2026-08-21T09:16:40.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries.\n\nThis issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.20.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-66721","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.327","lastModified":"2026-08-21T09:16:40.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing authorization issue for domain admins in CloudStack's host tags listing functionality.\n\n\n\n\nDomain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead be restricted to only the hosts dedicated to that admin's domain.\n\n\n\n\nThis issue affects Apache CloudStack: from 4.12.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\n\n\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.12.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-66722","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.460","lastModified":"2026-08-21T09:16:40.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack.\n\n\n\n\nA Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check only confirms the caller is a Domain Admin, without verifying whether the target project belongs to their domain or subdomain. This allows a malicious Domain Admin to tamper with project roles and permissions across unrelated domains.\n\n\n\n\nThis issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\n\n\n\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.15.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-66797","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.577","lastModified":"2026-08-21T09:16:40.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure.\n\n\n\n\nThe addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result correctly. This lets any authenticated user write annotations to, and disclose existing annotations/comments on, an entity they don't own by simply supplying its UUID.\n\n\n\n\nThis issue affects Apache CloudStack: from 4.15.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0.\n\n\n\n\n\nUsers are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.16.0.0","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-68745","sourceIdentifier":"security@apache.org","published":"2026-08-21T09:16:40.697","lastModified":"2026-08-21T09:16:40.697","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing registered in the management server, after which it can allow logging on with forged signatures.\n\nUsers are recommended to upgrade to versions 4.20.3.1 or 4.22.1.1 and above, which fix this issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache CloudStack","defaultStatus":"unaffected","versions":[{"version":"4.5.2","lessThanOrEqual":"4.20.3.0","versionType":"semver","status":"affected"},{"version":"4.21.0.0","lessThanOrEqual":"4.22.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"references":[{"url":"https://lists.apache.org/thread/g6cwddtjrwbh1d56wjz4cfp3fzfm4kbc","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-77710","sourceIdentifier":"5a6e4751-2f3f-4070-9419-94fb35b644e8","published":"2026-08-21T09:16:41.027","lastModified":"2026-08-21T09:16:41.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import.\n\nThe STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection.\n\nWhen STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the complete x_misp_attributes dictionary and passing it directly to misp_object.add_attribute(). Consequently, a crafted STIX bundle could supply fields that were not part of the expected STIX-to-MISP round-trip format, including security-sensitive properties such as distribution, sharing_group_id, tags, or other MISP attribute fields.\n\nAn attacker able to provide a STIX document for import could therefore spoof the markers used to identify MISP-generated content and inject additional attribute properties. This could alter the distribution, sharing restrictions, classification, or semantic metadata of imported attributes, potentially causing information to be shared contrary to the importing organization's policy or influencing downstream processing and automation based on attacker-controlled tags or metadata.\n\nThe vulnerability results from dynamically assigning externally supplied object properties without restricting them to an expected set of attributes, matching CWE-915. MITRE specifically describes this weakness as accepting externally influenced fields without controlling which object attributes may be modified and recommends an allow-list, which is the approach implemented by the patch. The parser-selection issue additionally corresponds to CWE-807, because an untrusted value was used to make a security-relevant trust/classification decision.\n\nThe attack is also consistent with CAPEC-153 (Input Data Manipulation), in which an attacker controls the structure or flags of supplied data so that the target selects a different processing path or interprets the content differently than intended."}],"affected":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","affectedData":[{"vendor":"MISP","product":"misp-stix","defaultStatus":"unaffected","repo":"https://github.com/MISP/misp-stix","versions":[{"version":"0","lessThanOrEqual":"2026.7.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://github.com/MISP/misp-stix/commit/3e5e7bda","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/MISP/misp-stix/commit/66c654b9","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}]}},{"cve":{"id":"CVE-2026-47827","sourceIdentifier":"security@vmware.com","published":"2026-08-21T10:16:38.647","lastModified":"2026-08-21T10:16:38.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities"}],"affected":[{"source":"security@vmware.com","affectedData":[{"vendor":"Cloud Foundry Foundation","product":"BOSH CLI","defaultStatus":"affected","packageName":"BOSH CLI","platforms":["Windows"],"versions":[{"version":"0.0","lessThan":"2.840.0","versionType":"OSS","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@vmware.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}]},"references":[{"url":"https://www.cloudfoundry.org/blog/cve-2026-47827-bosh-cli-powershell-injection/","source":"security@vmware.com"}]}},{"cve":{"id":"CVE-2026-77681","sourceIdentifier":"cna@vuldb.com","published":"2026-08-21T10:16:39.047","lastModified":"2026-08-21T10:16:39.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"CodeAstro","product":"Online Job Portal","cpes":["cpe:2.3:a:codeastro:online_job_portal:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-284"},{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://codeastro.com/","source":"cna@vuldb.com"},{"url":"https://github.com/Witiers/CVEs/issues/3","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-77681","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/881033","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394032","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394032/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-77751","sourceIdentifier":"5a6e4751-2f3f-4070-9419-94fb35b644e8","published":"2026-08-21T10:16:39.210","lastModified":"2026-08-21T10:16:39.210","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export.\n\nMISP object names are passed to PyMISP's object-template resolution mechanism, which constructs a filesystem path by joining the configured MISP object-template directory, the object name, and definition.json. An object name originating from untrusted STIX or MISP content was not sufficiently restricted before being used in this filesystem path.\n\nAn attacker able to supply a crafted object name containing path separators or traversal sequences such as ../ could therefore cause template resolution to escape the expected template directory and attempt to load a definition.json file from another location accessible to the process.\n\nDuring STIX 2 import, an attacker-controlled x_misp_name from a custom STIX object could directly reach this template-resolution mechanism.\n\nThe issue could also become persistent. A malicious object name stored in a MISP event could later be processed again during STIX 2 export. Consequently, content originally introduced in one security context could trigger filesystem access later when the event is exported by a process operating with different or greater privileges.\n\nIf a suitable definition.json file exists outside the intended template directory, its contents may be interpreted as a MISP object template and fields from that file copied into the converted object. This can result in unintended disclosure of locally accessible data represented by the template file and modification of the resulting object's metadata or semantics.\n\nThe patches introduce strict validation of object-template names. Valid names are restricted to a single path component containing letters, digits, hyphens, or underscores. Names that do not meet these requirements are replaced with the generic unknown-template name before reaching PyMISP template resolution. The original rejected name is preserved in the object's comment and a warning is generated, preventing traversal while retaining the source information."}],"affected":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","affectedData":[{"vendor":"misp","product":"misp-stix","defaultStatus":"unaffected","repo":"https://github.com/MISP/misp-stix/","versions":[{"version":"0","lessThanOrEqual":"2026.7.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/MISP/misp-stix/commit/a0f54070","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/MISP/misp-stix/commit/a8b6808d","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}]}}]}