Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 26 June 2026
RSS958 vulnerabilities published on 26 June 2026
Severity:
Kestra REST API allows unauthenticated access to sensitive data
CVE-2026-53576
Prior to Kestra version 1.0.45 and 1.3.21, an attacker could bypass authentication and create a flow that runs as the root user. This could allow the attacker to access sensitive data on the host syst...
10.0
Kestra: Unauthenticated Remote Code Execution via Public Configs
CVE-2026-49869
An open-source platform used for workflow orchestration has a security flaw that allows unauthorized access to its configuration settings. This can lead to unauthenticated users executing arbitrary co...
10.0
Apache Pinot MCP Server Exposes Data Without Password
CVE-2026-49257
GHSA-73cv-556c-w3g6
A security issue in mcp-pinot versions 3.0.1 and below allows unauthorized access to Apache Pinot data. This is because the MCP server does not require a password to connect, making it vulnerable to a...
10.0
WSO2 API Manager Allows Unauthenticated Destination Control
CVE-2026-2053
The WSO2 API Manager's message flow component does not properly check user input in certain headers. This allows an attacker to control where internal server requests go, potentially giving them acces...
10.0
Nezha Terminal/File Manager Session Hijacking via WebSocket
GHSA-q6xx-5vr8-p898
Nezha's terminal and file manager features have a security flaw that allows an attacker to take control of a session on a remote server. This can happen if an attacker learns the ID of a live session ...
9.9
Nezha allows cross-tenant access to terminal sessions
GHSA-q6xx-5vr8-p898
In Nezha versions v1.14.13 to v1.14.14 and v2.0.0 to v2.0.9, a user can access another user's live terminal sessions without permission. This allows an attacker to gain interactive shell access to the...
9.9
Deepstream Server Versions Prior to 10.0.5 Allow Unauthorized Access
CVE-2026-49252
GHSA-9v98-6g37-x9g6
Versions of the Deepstream server prior to 10.0.5 contain a security flaw that allows an authenticated user with write permission to access and modify sensitive data. This could potentially give the u...
9.9
OpenProject: Unsecured Timestamps in Project Management Software
CVE-2026-52785
OpenProject's project management software had a security weakness that could have allowed hackers to access sensitive information. This weakness has been fixed in versions 17.3.3 and 17.4.1, so users ...
9.9
OpenProject: Unauthorized Project Access via Project Settings
CVE-2026-52782
A project administrator in one project can access and manage the files of another project on the same storage. This is a security risk because it allows unauthorized access to sensitive project inform...
9.9
OpenProject Docker Image Exposes Master Key
CVE-2026-46386
OpenProject's Docker image exposes a sensitive key, which can be used by attackers to access user sessions. This is a security concern because it could allow unauthorized access to project management ...
9.9
Incus client writes files to arbitrary locations
GHSA-f6m5-xw2g-xc4x
CVE-2026-48769
GO-2026-5806
A malicious image server can write files to any location on the Incus server, potentially allowing an attacker to execute commands as root. This is due to a weakness in how Incus handles image downloa...
9.9
Incus allows attackers to write arbitrary files on the host
GHSA-v6mj-8pf4-hhw4
CVE-2026-48755
GO-2026-5808
A vulnerability in Incus's backup compression feature allows attackers to write arbitrary files on the host, potentially leading to unauthorized access. This issue affects Incus's backup compression f...
9.9
Incus S3 Multipart Upload allows arbitrary file creation
GHSA-ccjc-4qc3-jxqc
CVE-2026-48753
GO-2026-5802
A vulnerability in Incus's S3 protocol upload endpoint allows attackers to create arbitrary files on the host, potentially leading to unauthorized command execution. This affects Incus users who rely ...
9.9
Incus allows malicious images to read and write host files
GHSA-vxp5-584q-c479
CVE-2026-48752
GO-2026-5803
Incus, a container management software, can be tricked into allowing malicious images to read and write files on the host system. This could potentially allow an attacker to execute malicious code on ...
9.9
Incus allows malicious snapshots to bypass project restrictions
GHSA-48q5-w887-33wv
CVE-2026-48751
GO-2026-5799
Incus has a security issue that allows a malicious user to bypass project restrictions and execute arbitrary commands on the server with root privileges. This is a serious problem because it could all...
9.9
Incus allows arbitrary file writes via crafted images
GHSA-73hr-m85f-64v9
CVE-2026-48750
GO-2026-5801
A vulnerability in Incus allows attackers to write files to arbitrary locations on the host system by creating a specially crafted image. This can potentially lead to unauthorized command execution. T...
9.9
Incus allows malicious images to access host files
GHSA-2q3f-q5pq-g8wv
CVE-2026-48749
GO-2026-5798
A malicious image can read and write any file on the host, potentially allowing an attacker to execute any command. This is a serious security risk, and users should be cautious when importing images ...
9.9
Dokku Docker Container Escalation via Malicious App Config
CVE-2026-54636
A configuration mistake in Dokku's app settings can allow an attacker to run commands on the server as the Dokku user. This could lead to unauthorized access and potentially allow the attacker to take...
9.9
Travel Booking <= 2.2.5: Unsecured File Uploads
CVE-2026-56059
Travel Booking software versions 2.2.5 and earlier allow attackers to upload unauthorized files. This could lead to malicious code being executed on the server, potentially compromising the entire sys...
9.9
Quform <= 2.23.0: Unrestricted File Upload in Quform
CVE-2026-56058
Quform, a WordPress plugin, allows attackers to upload any file on the server. This can lead to unauthorized data access or server compromise. Update Quform to version 2.24.0 or later to fix this issu...
9.9
Booster for WooCommerce <= 8.0.1 allows customers to upload arbitrary files
CVE-2026-56027
The Booster for WooCommerce plugin allows customers to upload files without proper validation, which means they can potentially upload malicious files. This could lead to security risks and compromise...
9.9
DMP-5000 devices have a default admin account with weak security
CVE-2026-31928
DMP-5000 security devices come with a default admin account that isn't changed during setup. This allows unauthorized access to the device's system. To fix this, change the admin account password imme...
9.3
FFmpeg before 8.1 allows malicious media files to crash or execute code
JLSEC-2026-652
A security issue in FFmpeg's media handling could allow attackers to create malicious media files that can cause FFmpeg to crash or potentially execute unauthorized code. This affects users who proces...
9.8
Linux Kernel: Incorrect Loop Condition in ocfs2/dlm
CVE-2026-53309
A bug in the Linux kernel's ocfs2/dlm module could cause it to access memory outside its intended range, potentially leading to crashes or other issues. This issue has been fixed in the latest kernel ...
9.8
Linux Kernel: Off-by-One Error in Region Comparison
DEBIAN-CVE-2026-53309
A bug in the Linux kernel's region comparison loop has been fixed. This bug could have allowed an attacker to read or write data outside of allowed areas, potentially leading to data corruption or sec...
9.8