<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the jpcert CNA root</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Latest vulnerabilities published by the CNAs operating under the jpcert root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:14 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-78249 (FB)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-78249</link>
      <description>A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of externally supplied parameters. 

If the device receives a specially crafted, malicious request, it may trigger unintended processing.</description>
      <content:encoded>A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of externally supplied parameters. 

If the device receives a specially crafted, malicious request, it may trigger unintended processing.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-78249</guid>
      <pubDate>Thu, 01 Oct 2026 07:56:26 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82824 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82824</link>
      <description>Path traversal may allow arbitrary files to be viewed, created, modified, or deleted</description>
      <content:encoded>Path traversal may allow arbitrary files to be viewed, created, modified, or deleted</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82824</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:58 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82825 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82825</link>
      <description>Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed</description>
      <content:encoded>Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82825</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:57 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82826 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82826</link>
      <description>Authentication information or sensitive data may be intercepted in transit</description>
      <content:encoded>Authentication information or sensitive data may be intercepted in transit</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82826</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82827 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82827</link>
      <description>A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens</description>
      <content:encoded>A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82827</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82828 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82828</link>
      <description>Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges</description>
      <content:encoded>Improper authorization may allow a general user to perform operations equivalent to those available with administrator privileges</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82828</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:54 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-82829 (Hitachi)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-82829</link>
      <description>Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process</description>
      <content:encoded>Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-82829</guid>
      <pubDate>Thu, 01 Oct 2026 04:57:53 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-92873 (jpcert)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92873</link>
      <description>Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.</description>
      <content:encoded>Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92873</guid>
      <pubDate>Wed, 30 Sep 2026 07:51:52 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-92872 (jpcert)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92872</link>
      <description>Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.</description>
      <content:encoded>Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92872</guid>
      <pubDate>Wed, 30 Sep 2026 07:47:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-92871 (jpcert)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-92871</link>
      <description>A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.</description>
      <content:encoded>A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-92871</guid>
      <pubDate>Wed, 30 Sep 2026 07:47:32 +0000</pubDate>
    </item>
  </channel>
</rss>
