<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/cna-root/jpcert/recent</id>
  <title>Most recent vulnerabilities from the jpcert CNA root</title>
  <updated>2026-10-02T07:10:14.518539+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the jpcert root of the CVE Program.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-78249</id>
    <title>CVE-2026-78249 (FB)</title>
    <updated>2026-10-01T07:56:26.289000+00:00</updated>
    <content>A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of externally supplied parameters. 

If the device receives a specially crafted, malicious request, it may trigger unintended processing.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-78249"/>
    <summary>A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of externally supplied parameters. 

If the device receives a specially crafted, malicious request, it may trigger unintended processing.</summary>
    <published>2026-10-01T07:56:26.289000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82824</id>
    <title>CVE-2026-82824 (Hitachi)</title>
    <updated>2026-10-01T04:57:58.485000+00:00</updated>
    <content>Path traversal may allow arbitrary files to be viewed, created, modified, or deleted</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82824"/>
    <summary>Path traversal may allow arbitrary files to be viewed, created, modified, or deleted</summary>
    <published>2026-10-01T04:57:58.485000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82825</id>
    <title>CVE-2026-82825 (Hitachi)</title>
    <updated>2026-10-01T04:57:57.577000+00:00</updated>
    <content>Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82825"/>
    <summary>Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed</summary>
    <published>2026-10-01T04:57:57.577000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82826</id>
    <title>CVE-2026-82826 (Hitachi)</title>
    <updated>2026-10-01T04:57:56.651000+00:00</updated>
    <content>Authentication information or sensitive data may be intercepted in transit</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82826"/>
    <summary>Authentication information or sensitive data may be intercepted in transit</summary>
    <published>2026-10-01T04:57:56.651000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82827</id>
    <title>CVE-2026-82827 (Hitachi)</title>
    <updated>2026-10-01T04:57:55.728000+00:00</updated>
    <content>A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82827"/>
    <summary>A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens</summary>
    <published>2026-10-01T04:57:55.728000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82828</id>
    <title>CVE-2026-82828 (Hitachi)</title>
    <updated>2026-10-01T04:57:54.765000+00:00</updated>
    <content>Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82828"/>
    <summary>Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges</summary>
    <published>2026-10-01T04:57:54.765000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-82829</id>
    <title>CVE-2026-82829 (Hitachi)</title>
    <updated>2026-10-01T04:57:53.541000+00:00</updated>
    <content>Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-82829"/>
    <summary>Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process</summary>
    <published>2026-10-01T04:57:53.541000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-92873</id>
    <title>CVE-2026-92873 (jpcert)</title>
    <updated>2026-09-30T07:51:52.401000+00:00</updated>
    <content>Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-92873"/>
    <summary>Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.</summary>
    <published>2026-09-30T07:51:52.401000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-92872</id>
    <title>CVE-2026-92872 (jpcert)</title>
    <updated>2026-09-30T07:47:50.234000+00:00</updated>
    <content>Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-92872"/>
    <summary>Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.</summary>
    <published>2026-09-30T07:47:50.234000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-92871</id>
    <title>CVE-2026-92871 (jpcert)</title>
    <updated>2026-09-30T07:47:32.091000+00:00</updated>
    <content>A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-92871"/>
    <summary>A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.</summary>
    <published>2026-09-30T07:47:32.091000+00:00</published>
  </entry>
</feed>
