Common Weakness Enumeration

CWE-287

Discouraged

Improper Authentication

Abstraction: Class · Status: Draft

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

6771 vulnerabilities reference this CWE, most recent first.

CVE-2026-103651 (GCVE-0-2026-103651)

Vulnerability from cvelistv5 – Published: 2026-10-01 07:34 – Updated: 2026-10-01 15:32
VLAI
Title
MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass
Summary
MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state. Preconditions: - The target user has HOTP (paper token) second-factor authentication enabled. - The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending). - The attacker has access to at least one HOTP token value (e.g., a paper token list). Security impact: - Bypass of the second authentication factor, allowing unauthorized access to a user's MISP account. - Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays. Affected versions: <2.5.48.
SSVC
Exploitation: none Automatable: no Technical Impact: total
Supplier · CIRCL (v2.0.3)
Decision recorded 2026-10-01 07:22 UTC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:31 UTC
CWE
  • CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
  • CWE-287 - Improper Authentication
References
Impacted products
Vendor Product Version
MISP MISP Affected: 0 , < 2.5.48 (semver)
    cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
Create a notification for this product.
GCVE extensions
bcp-05-x-01
AI-assisted vulnerability information annotation
GCVE-BCP-05-X-01
Whole record AI-generated Human-reviewed GNA-1

Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.

ai-computer-assisted:llm-generatedai-computer-assisted:classification
Model Source Identifier
qwen3.8:27b ollama qwen3.8:27b
bcp-05-x-02
Patch-to-vulnerability generation provenance
GCVE-BCP-05-X-02
Generator
patch2vuln.py on 2026-10-01 07:22
Model
qwen3.8:27b
Input
https://github.com/MISP/MISP/commit/f34aee2c7.patch 9ec05e4a3d95…
Confidence
medium
Commit Subject Patch SHA-256
f34aee2c74e1 fix: [security] Burn paper OTP tokens against the stored 9ec05e4a3d95…
Fix summary

The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.

Patch summary

In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user['hotp_counter']) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user's totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.

CVSS rationale

AV:N – MISP is a network-accessible web application. AC:H – exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N – no manipulation of the target system is needed. PR:L – the attacker must be an authenticated user with a pending OTP session. UI:N – no additional user interaction is required beyond the initial login flow. VC:H – successful exploitation grants full access to the target user's MISP account and its data. VI:H – the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N – no denial-of-service impact is evident. SC/SI/SA:N – no secondary system impact is indicated by the patch.

Weakness rationale
  • CWE-362 The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value.
  • CWE-287 The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check.
Attack pattern rationale
  • CAPEC-111 The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match.
Assumptions to verify
  • The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.
  • The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.
  • CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.
  • The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.
  • The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer.
Model comparison

Selected qwen3.8:27b by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.

Model Score Agreement Confidence Assumptions
qwen3.8:27b 7 11 medium 5
bcp-05-x-03
Vulnerability handling and disclosure timeline
GCVE-BCP-05-X-03
  1. 2026-09-23 14:20 UTC Fix developed Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored https://github.com/MISP/MISP/commit/f34aee2c7.patch
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103651",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T15:31:56.170497Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T15:32:08.372Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "app/Controller/UsersController.php"
          ],
          "product": "MISP",
          "programFiles": [
            "app/Controller/UsersController.php"
          ],
          "repo": "https://github.com/MISP/MISP",
          "vendor": "MISP",
          "versions": [
            {
              "lessThan": "2.5.48",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Tanguy Snoeck of NCIA"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "iglocska"
        },
        {
          "lang": "en",
          "type": "remediation developer",
          "value": "Claude Opus 5.5 (1M context)"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eMISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\u003c/p\u003e\u003cp\u003eThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- The target user has HOTP (paper token) second-factor authentication enabled.\u003c/p\u003e\u003cp\u003e- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\u003c/p\u003e\u003cp\u003e- The attacker has access to at least one HOTP token value (e.g., a paper token list).\u003c/p\u003e\u003cp\u003eSecurity impact:\u003c/p\u003e\u003cp\u003e- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\u003c/p\u003e\u003cp\u003e- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\u003c/p\u003e\u003cp\u003eAffected versions: \u0026lt;2.5.48.\u003c/p\u003e"
            }
          ],
          "value": "MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter.\n\nThe HOTP verification logic compared the submitted token against a counter value that was cached in the user\u0027s session at the time the password was entered, rather than against the authoritative counter stored in the database. Because the session-cached counter is not updated after a token is successfully consumed, an attacker who holds a valid session (password already submitted) can reuse a previously burned HOTP token. The stale cached counter still matches the replayed token, granting a second successful authentication and effectively rewinding the counter state.\n\nPreconditions:\n\n- The target user has HOTP (paper token) second-factor authentication enabled.\n\n- The attacker possesses a valid session in which the password step has already been completed (the OTP step is pending).\n\n- The attacker has access to at least one HOTP token value (e.g., a paper token list).\n\nSecurity impact:\n\n- Bypass of the second authentication factor, allowing unauthorized access to a user\u0027s MISP account.\n\n- Corruption of the HOTP counter state, potentially invalidating subsequent legitimate tokens or enabling further replays.\n\nAffected versions: \u003c2.5.48."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-111",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-111 Race Condition"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.6,
            "baseSeverity": "HIGH",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "format": "SSVC",
          "other": {
            "content": {
              "options": [
                {
                  "Exploitation": "none"
                },
                {
                  "Automatable": "no"
                },
                {
                  "Technical Impact": "total"
                }
              ],
              "role": "Supplier",
              "timestamp": "2026-10-01T07:22:27Z",
              "version": "2.0.3"
            },
            "type": "SSVC"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-362",
              "description": "CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "CWE-287 Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T07:34:02.597Z",
        "orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
        "shortName": "CIRCL"
      },
      "references": [
        {
          "name": "Security patch",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/MISP/MISP/commit/f34aee2c7"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.\u003c/p\u003e"
            }
          ],
          "value": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused."
        }
      ],
      "title": "MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass",
      "x_gcve": [
        {
          "extensions": {
            "bcp-05-x-01": {
              "ai_annotations": [
                {
                  "ai_level": "generated",
                  "description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
                  "gna_source": 1,
                  "models": [
                    {
                      "gna_source": 1,
                      "identifier": "qwen3.8:27b",
                      "name": "qwen3.8:27b",
                      "source": "ollama"
                    }
                  ],
                  "review_status": "full",
                  "scope": "record",
                  "tags": [
                    "ai-computer-assisted:llm-generated",
                    "ai-computer-assisted:classification"
                  ]
                }
              ]
            },
            "bcp-05-x-02": {
              "x_patch2vuln": {
                "assumptions": [
                  "The tag_version_boundary metadata (v2.5.48, 41 commits after fix) is interpreted as the first release containing the fix; no explicit fixed_version or affected_version was provided in the metadata.",
                  "The CAPEC-111 mapping is the closest available pattern; the vulnerability is specifically a stale-session-cache replay rather than a classic TOCTOU race, and no more precise CAPEC exists in the catalog.",
                  "CVSS PR:L assumes the attacker already has a valid authenticated session (password step completed); if the threat model requires unauthenticated access, PR would be None but AC would remain High.",
                  "The Redis lock is assumed to be available in the deployment; if Redis is not configured, the locking mechanism may be bypassed, though this is a deployment concern not reflected in the patch.",
                  "The Co-Authored-By line references an AI assistant; it is recorded as a tool credit rather than a human remediation developer."
                ],
                "capecRationale": [
                  {
                    "capecId": "CAPEC-111",
                    "rationale": "The vulnerability is exploited by exploiting the time window between the session-cached counter being set (at password entry) and the token being consumed, allowing a replayed token to be validated against the stale value. CAPEC-111 (Race Condition) is the closest available CAPEC pattern; the attack is not a classic TOCTOU on a file or memory location but rather a stale-cache race on a shared counter, which falls under the broader race-condition category. No more specific CAPEC for session-cached credential state replay exists in the CAPEC catalog, so this is the best available match."
                  }
                ],
                "commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
                "confidence": "medium",
                "credits": [
                  {
                    "lang": "en",
                    "type": "reporter",
                    "value": "Tanguy Snoeck of NCIA"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "iglocska"
                  },
                  {
                    "lang": "en",
                    "type": "remediation developer",
                    "value": "Claude Opus 5.5 (1M context)"
                  }
                ],
                "cvssRationale": "AV:N \u2013 MISP is a network-accessible web application. AC:H \u2013 exploitation requires a valid session with the password step already completed, possession of a valid HOTP token value, and the session must still hold the stale cached counter; multiple preconditions must align. AT:N \u2013 no manipulation of the target system is needed. PR:L \u2013 the attacker must be an authenticated user with a pending OTP session. UI:N \u2013 no additional user interaction is required beyond the initial login flow. VC:H \u2013 successful exploitation grants full access to the target user\u0027s MISP account and its data. VI:H \u2013 the attacker can perform any action the user is authorized to perform, and the counter corruption may affect subsequent legitimate authentication. VA:N \u2013 no denial-of-service impact is evident. SC/SI/SA:N \u2013 no secondary system impact is indicated by the patch.",
                "fixSummary": "The fix replaces the session-cached HOTP counter lookup with a direct read of the authoritative counter from the database, performed under a Redis-based distributed lock scoped to the user. The token is verified against the current stored counter, the counter is incremented and persisted atomically within the locked section, and the lock is released in a finally block. Additionally, the cached OTP user session entry is deleted immediately after a successful login (for both TOTP and HOTP paths), preventing the stale session state from being reused.",
                "generatedAt": "2026-10-01T07:22:27.568266Z",
                "generator": "patch2vuln.py",
                "model": "qwen3.8:27b",
                "modelComparison": {
                  "rankings": [
                    {
                      "agreementScore": 11,
                      "assumptionCount": 5,
                      "confidence": "medium",
                      "model": "qwen3.8:27b",
                      "score": 7
                    }
                  ],
                  "selectedModel": "qwen3.8:27b",
                  "selectionMethod": "deterministic-consensus-v1",
                  "selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
                },
                "patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
                "patchSummary": "In UsersController::otp(), the inline HOTP verification block (which used the session-cached $user[\u0027hotp_counter\u0027]) is replaced with a call to a new private method __consumeHotp(). This method acquires a Redis SETNX lock (misp:otp:hotp_lock:{userId}, 10 s TTL), re-fetches the user\u0027s totp secret and hotp_counter from the database, verifies the submitted OTP against the stored counter, increments and saves the counter, and releases the lock in a finally block. The otp_user session key is now deleted after both TOTP and HOTP successful login paths. Net change: +36 / -5 lines in app/Controller/UsersController.php.",
                "patchTruncated": false,
                "patches": [
                  {
                    "commit": "f34aee2c74e111fffd07e8ddde8e4843ccf998db",
                    "date": "Wed, 23 Sep 2026 16:20:38 +0200",
                    "patchSha256": "9ec05e4a3d95b183604c7e89e3fbb93950ac4d23dfe478809b868b6dfe85bad6",
                    "source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
                    "sourceUrl": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
                    "subject": "fix: [security] Burn paper OTP tokens against the stored"
                  }
                ],
                "source": "https://github.com/MISP/MISP/commit/f34aee2c7.patch",
                "ssvc": {
                  "options": [
                    {
                      "Exploitation": "none"
                    },
                    {
                      "Automatable": "no"
                    },
                    {
                      "Technical Impact": "total"
                    }
                  ],
                  "role": "Supplier",
                  "timestamp": "2026-10-01T07:22:27Z",
                  "version": "2.0.3"
                },
                "subject": "fix: [security] Burn paper OTP tokens against the stored",
                "tagVersionBoundary": {
                  "commits_after_fix": 41,
                  "repository": "https://github.com/MISP/MISP",
                  "tag": "v2.5.48",
                  "version": "2.5.48",
                  "version_type": "semver"
                },
                "weaknessRationale": [
                  {
                    "cweId": "CWE-362",
                    "rationale": "The HOTP counter is shared mutable state accessed without synchronization. The session-cached copy becomes stale relative to the database copy, and no lock is held during read-verify-increment, allowing a concurrent or replayed request to operate on the old value."
                  },
                  {
                    "cweId": "CWE-287",
                    "rationale": "The OTP verification logic accepts a token that has already been consumed because it compares against a stale cached counter rather than the authoritative stored counter, effectively weakening the second-factor authentication check."
                  }
                ]
              }
            },
            "bcp-05-x-03": {
              "x_timeline": {
                "events": [
                  {
                    "description": "Corrective change authored (f34aee2c74e111fffd07e8ddde8e4843ccf998db): fix: [security] Burn paper OTP tokens against the stored",
                    "id": "evt-fix-developed-1",
                    "references": [
                      "https://github.com/MISP/MISP/commit/f34aee2c7.patch"
                    ],
                    "timestamp": "2026-09-23T14:20:38Z",
                    "type": "fix-developed"
                  }
                ]
              }
            }
          },
          "recordType": "advisory",
          "vulnId": "GCVE-1-2026-20307"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
    "assignerShortName": "CIRCL",
    "cveId": "CVE-2026-103651",
    "datePublished": "2026-10-01T07:34:02.597Z",
    "dateReserved": "2026-10-01T07:34:00.794Z",
    "dateUpdated": "2026-10-01T15:32:08.372Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103539 (GCVE-0-2026-103539)

Vulnerability from cvelistv5 – Published: 2026-10-01 05:00 – Updated: 2026-10-01 05:00
VLAI
Title
ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication
Summary
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CWE
References
URL Tags
https://vuldb.com/vuln/412349 vdb-entrytechnical-description
https://vuldb.com/vuln/412349/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-103539 third-party-advisory
https://vuldb.com/submit/957826 third-party-advisory
https://github.com/ZongXR/SuperMarket/issues/30 exploitissue-tracking
https://github.com/ZongXR/SuperMarket/ product
Impacted products
Vendor Product Version
ZongXR SuperMarket Affected: 1.0.0.0
    cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Instant Buy"
          ],
          "product": "SuperMarket",
          "vendor": "ZongXR",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "360alphalab (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 5.5,
            "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "Missing Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T05:00:09.463Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412349 | ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412349"
        },
        {
          "name": "VDB-412349 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412349/cti"
        },
        {
          "name": "CVE-2026-103539 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-103539"
        },
        {
          "name": "Submit #957826 | ZongXR SuperMarket master Missing Authentication",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/957826"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/issues/30"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-30T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-30T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-30T21:12:33.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-103539",
    "datePublished": "2026-10-01T05:00:09.463Z",
    "dateReserved": "2026-09-30T19:07:24.604Z",
    "dateUpdated": "2026-10-01T05:00:09.463Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103538 (GCVE-0-2026-103538)

Vulnerability from cvelistv5 – Published: 2026-10-01 04:30 – Updated: 2026-10-01 14:16
VLAI
Title
ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication
Summary
A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:15 UTC
CWE
References
URL Tags
https://vuldb.com/vuln/412348 vdb-entrytechnical-description
https://vuldb.com/vuln/412348/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-103538 third-party-advisory
https://vuldb.com/submit/957825 third-party-advisory
https://github.com/ZongXR/SuperMarket/issues/31 exploitissue-tracking
https://github.com/ZongXR/SuperMarket/ product
Impacted products
Vendor Product Version
ZongXR SuperMarket Affected: 1.0.0.0
    cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103538",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T14:15:48.796370Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T14:16:00.889Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Order Deletion Endpoint"
          ],
          "product": "SuperMarket",
          "vendor": "ZongXR",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "360alphalab (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 6.4,
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "Missing Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T04:30:11.829Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412348 | ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412348"
        },
        {
          "name": "VDB-412348 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412348/cti"
        },
        {
          "name": "CVE-2026-103538 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-103538"
        },
        {
          "name": "Submit #957825 | ZongXR SuperMarket master Missing Authentication",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/957825"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/issues/31"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-30T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-30T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-30T21:12:27.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-103538",
    "datePublished": "2026-10-01T04:30:11.829Z",
    "dateReserved": "2026-09-30T19:07:18.677Z",
    "dateUpdated": "2026-10-01T14:16:00.889Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103536 (GCVE-0-2026-103536)

Vulnerability from cvelistv5 – Published: 2026-10-01 04:15 – Updated: 2026-10-01 19:09
VLAI
Title
ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication
Summary
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:08 UTC
CWE
References
URL Tags
https://vuldb.com/vuln/412347 vdb-entrytechnical-description
https://vuldb.com/vuln/412347/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-103536 third-party-advisory
https://vuldb.com/submit/957824 third-party-advisory
https://github.com/ZongXR/SuperMarket/issues/32 exploitissue-tracking
https://github.com/ZongXR/SuperMarket/ product
Impacted products
Vendor Product Version
ZongXR Supermarket Affected: 1.0.0.0
    cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103536",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T19:08:38.108441Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T19:09:19.697Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "save Endpoint"
          ],
          "product": "Supermarket",
          "vendor": "ZongXR",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.0"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "360alphalab (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "Missing Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T04:15:10.029Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-412347 | ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
          "tags": [
            "vdb-entry",
            "technical-description"
          ],
          "url": "https://vuldb.com/vuln/412347"
        },
        {
          "name": "VDB-412347 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/412347/cti"
        },
        {
          "name": "CVE-2026-103536 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-103536"
        },
        {
          "name": "Submit #957824 | ZongXR SuperMarket master Missing Authentication",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/957824"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/issues/32"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/ZongXR/SuperMarket/"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-30T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-30T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-30T21:12:20.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
      "x_generator": [
        "VulDB PVTS v202610"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-103536",
    "datePublished": "2026-10-01T04:15:10.029Z",
    "dateReserved": "2026-09-30T19:07:13.098Z",
    "dateUpdated": "2026-10-01T19:09:19.697Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103264 (GCVE-0-2026-103264)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:42 – Updated: 2026-10-01 13:32
VLAI
Title
Fleet before 4.87.0 Authentication Bypass via Device Identifiers
Summary
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:30 UTC
CWE
  • CWE-287 - Improper Authentication
References
Impacted products
Vendor Product Version
fleetdm fleet Affected: 0 , < 4.87.0 (semver)
Unaffected: 4.87.0 (semver)
    cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-09-15 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103264",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T13:30:37.558254Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T13:32:04.417Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "packageURL": "pkg:golang/github.com/fleetdm/fleet",
          "product": "fleet",
          "vendor": "fleetdm",
          "versions": [
            {
              "lessThan": "4.87.0",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.87.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.87.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2026-09-15T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "privilegesRequired": "NONE",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:42:06.306Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "GitHub Security Advisory (GHSA-vrc8-2wcx-327f)",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/fleetdm/fleet/security/advisories/GHSA-vrc8-2wcx-327f"
        },
        {
          "name": "VulnCheck Advisory: Fleet before 4.87.0 Authentication Bypass via Device Identifiers",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/fleet-before-4.87.0-authentication-bypass-via-device-identifiers"
        }
      ],
      "title": "Fleet before 4.87.0 Authentication Bypass via Device Identifiers",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-103264",
    "datePublished": "2026-10-01T10:42:06.306Z",
    "dateReserved": "2026-09-30T10:58:33.573Z",
    "dateUpdated": "2026-10-01T13:32:04.417Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102369 (GCVE-0-2026-102369)

Vulnerability from cvelistv5 – Published: 2026-10-01 17:42 – Updated: 2026-10-01 18:08
VLAI
Title
Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:07 UTC
CWE
  • CWE-287 - Improper Authentication
Impacted products
Vendor Product Version
TP-Link Systems Inc. Tapo C200 v5 Affected: 0 , < V5_1.4.6 Build 260709 Rel.27675n (custom)
Create a notification for this product.
TP-Link Systems Inc. Tapo C120 v1 Affected: 0 , < V1_1.9.4 Build 260813 Rel.79754n (custom)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102369",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T18:07:54.890490Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T18:08:05.015Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Tapo C200 v5",
          "vendor": "TP-Link Systems Inc.",
          "versions": [
            {
              "lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Tapo C120 v1",
          "vendor": "TP-Link Systems Inc.",
          "versions": [
            {
              "lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eTapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot.\u003c/p\u003e"
            }
          ],
          "value": "Tapo C120 v1 and C200 V5\ndo not adequately protect login challenge data or sanitize\nattacker-controlled input processed by the MacTool handler. An unauthenticated\nattacker on the same local network can replay login challenge data to obtain an\nadministrative session, enable a privileged service that becomes accessible\nafter a reboot, and submit crafted input to execute arbitrary commands within\nthe device management process.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow arbitrary command execution on the camera and compromise\nthe confidentiality, integrity, and availability of the affected device.\nExploitation requires access from the same local network, replay of the login\nchallenge data, activation of the privileged service, and a device reboot."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-21",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-21 Exploitation of Trusted Identifiers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "ADJACENT",
            "baseScore": 8.7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "CWE-287 Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T17:42:25.482Z",
        "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "shortName": "TPLink"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.tp-link.com/us/support/faq/5321/"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 \u0026 C200",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
    "assignerShortName": "TPLink",
    "cveId": "CVE-2026-102369",
    "datePublished": "2026-10-01T17:42:25.482Z",
    "dateReserved": "2026-09-28T23:02:41.717Z",
    "dateUpdated": "2026-10-01T18:08:05.015Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102364 (GCVE-0-2026-102364)

Vulnerability from cvelistv5 – Published: 2026-09-28 23:34 – Updated: 2026-09-29 17:34
VLAI
Title
mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API
Summary
mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 17:34 UTC
CWE
  • CWE-287 - Improper Authentication
Impacted products
Vendor Product Version
gz-yami mall4j Affected: 0 , ≤ 4.0 (custom)
Create a notification for this product.
Date Public
2026-09-19 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102364",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-29T17:34:45.793647Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-29T17:34:55.288Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://github.com/gz-yami/mall4j",
          "defaultStatus": "unaffected",
          "product": "mall4j",
          "repo": "https://github.com/gz-yami/mall4j",
          "vendor": "gz-yami",
          "versions": [
            {
              "lessThanOrEqual": "4.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Mingsheng Lin"
        }
      ],
      "datePublic": "2026-09-19T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "privilegesRequired": "LOW",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW"
          },
          "format": "CVSS"
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-28T23:34:29.221Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A05_sys_menu_missing_perm.py"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A09_admin_read_endpoints_bfla.py"
        },
        {
          "tags": [
            "product"
          ],
          "url": "https://github.com/gz-yami/mall4j"
        },
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-security/yami-shop-security-common/src/main/java/com/yami/shop/security/common/filter/AuthFilter.java#L60-L119"
        },
        {
          "name": "VulnCheck Advisory: mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/mall4j-through-4.0-improper-authentication-accepts-storefront-tokens-on-admin-api"
        }
      ],
      "title": "mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-102364",
    "datePublished": "2026-09-28T23:34:29.221Z",
    "dateReserved": "2026-09-28T22:50:19.220Z",
    "dateUpdated": "2026-09-29T17:34:55.288Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102248 (GCVE-0-2026-102248)

Vulnerability from cvelistv5 – Published: 2026-09-29 03:30 – Updated: 2026-09-29 17:00
VLAI
Title
Rebuild Login Endpoint login improper authentication
Summary
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 16:59 UTC
CWE
  • CWE-287 - Improper Authentication
References
URL Tags
https://vuldb.com/vuln/411150 vdb-entry
https://vuldb.com/vuln/411150/cti signaturepermissions-required
https://vuldb.com/cve/CVE-2026-102248 third-party-advisory
https://vuldb.com/submit/933708 third-party-advisory
https://github.com/ASantsSec/CVE/issues/25 exploitissue-tracking
Impacted products
Vendor Product Version
n/a Rebuild Affected: 4.4.0
Affected: 4.4.1
Affected: 4.4.2
Affected: 4.4.3
Affected: 4.4.4
Affected: 4.4.5
Affected: 4.4.6
Affected: 4.4.7
Affected: 4.5.0-beta1
Affected: 4.5.0-beta2
Affected: 4.5.0-beta3
Affected: 4.5.0-beta4
Affected: 4.5.0-beta5
    cpe:2.3:a:rebuild:rebuild:*:*:*:*:*:*:*:*
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102248",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-29T16:59:56.902528Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-29T17:00:11.613Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:rebuild:rebuild:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Login Endpoint"
          ],
          "product": "Rebuild",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "4.4.0"
            },
            {
              "status": "affected",
              "version": "4.4.1"
            },
            {
              "status": "affected",
              "version": "4.4.2"
            },
            {
              "status": "affected",
              "version": "4.4.3"
            },
            {
              "status": "affected",
              "version": "4.4.4"
            },
            {
              "status": "affected",
              "version": "4.4.5"
            },
            {
              "status": "affected",
              "version": "4.4.6"
            },
            {
              "status": "affected",
              "version": "4.4.7"
            },
            {
              "status": "affected",
              "version": "4.5.0-beta1"
            },
            {
              "status": "affected",
              "version": "4.5.0-beta2"
            },
            {
              "status": "affected",
              "version": "4.5.0-beta3"
            },
            {
              "status": "affected",
              "version": "4.5.0-beta4"
            },
            {
              "status": "affected",
              "version": "4.5.0-beta5"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "asants (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T03:30:15.312Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-411150 | Rebuild Login Endpoint login improper authentication",
          "tags": [
            "vdb-entry"
          ],
          "url": "https://vuldb.com/vuln/411150"
        },
        {
          "name": "VDB-411150 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/411150/cti"
        },
        {
          "name": "CVE-2026-102248 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-102248"
        },
        {
          "name": "Submit #933708 | REBUILD 4.4.7-release Improper Authentication",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/933708"
        },
        {
          "tags": [
            "exploit",
            "issue-tracking"
          ],
          "url": "https://github.com/ASantsSec/CVE/issues/25"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-28T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-28T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-28T21:09:43.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "Rebuild Login Endpoint login improper authentication",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-102248",
    "datePublished": "2026-09-29T03:30:15.312Z",
    "dateReserved": "2026-09-28T19:04:31.218Z",
    "dateUpdated": "2026-09-29T17:00:11.613Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102245 (GCVE-0-2026-102245)

Vulnerability from cvelistv5 – Published: 2026-09-29 03:00 – Updated: 2026-10-01 15:39
VLAI
Title
MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication
Summary
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:39 UTC
CWE
References
Impacted products
Vendor Product Version
MODSetter SurfSense Affected: 2.0.0
Affected: 2.0.1
Affected: 2.0.2
Affected: 2.0.3
    cpe:2.3:a:modsetter:surfsense:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102245",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T15:39:19.173959Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T15:39:28.598Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:modsetter:surfsense:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "circleback Endpoint"
          ],
          "product": "SurfSense",
          "vendor": "MODSetter",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            },
            {
              "status": "affected",
              "version": "2.0.1"
            },
            {
              "status": "affected",
              "version": "2.0.2"
            },
            {
              "status": "affected",
              "version": "2.0.3"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Snkn0w (VulDB User)"
        },
        {
          "lang": "en",
          "type": "coordinator",
          "value": "VulDB CNA Team"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
            "version": "4.0"
          }
        },
        {
          "cvssV3_1": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.1"
          }
        },
        {
          "cvssV3_0": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
            "version": "3.0"
          }
        },
        {
          "cvssV2_0": {
            "baseScore": 7.5,
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
            "version": "2.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "Missing Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T03:00:15.001Z",
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB"
      },
      "references": [
        {
          "name": "VDB-411143 | MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication",
          "tags": [
            "vdb-entry"
          ],
          "url": "https://vuldb.com/vuln/411143"
        },
        {
          "name": "VDB-411143 | CTI Indicators (IOB, IOC, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ],
          "url": "https://vuldb.com/vuln/411143/cti"
        },
        {
          "name": "CVE-2026-102245 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/cve/CVE-2026-102245"
        },
        {
          "name": "Submit #933653 | MODSetter SurfSense \u003c=0.0.36 Missing Authorization",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://vuldb.com/submit/933653"
        },
        {
          "tags": [
            "exploit"
          ],
          "url": "https://gist.github.com/DReazer/1e476832e48bcdb2b4f732689dfeac0c"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-28T00:00:00.000Z",
          "value": "Advisory disclosed"
        },
        {
          "lang": "en",
          "time": "2026-09-28T02:00:00.000Z",
          "value": "VulDB entry created"
        },
        {
          "lang": "en",
          "time": "2026-09-28T20:51:35.000Z",
          "value": "VulDB entry last update"
        }
      ],
      "title": "MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication",
      "x_generator": [
        "VulDB PVTS v202609"
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "cveId": "CVE-2026-102245",
    "datePublished": "2026-09-29T03:00:15.001Z",
    "dateReserved": "2026-09-28T18:46:21.600Z",
    "dateUpdated": "2026-10-01T15:39:28.598Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-102128 (GCVE-0-2026-102128)

Vulnerability from cvelistv5 – Published: 2026-09-30 20:14 – Updated: 2026-10-01 13:37
VLAI
Title
Kiteworks Email Protection Gateway Improper Authentication
Summary
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:28 UTC
CWE
  • CWE-287 - Improper Authentication
References
Impacted products
Vendor Product Version
Kiteworks Email Protection Gateway Affected: 0 , < 9.5.1 (custom)
Unaffected: 9.5.1
Create a notification for this product.
Date Public
2026-09-30 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-102128",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T13:28:15.954252Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T13:37:05.460Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "Email Protection Gateway",
          "vendor": "Kiteworks",
          "versions": [
            {
              "lessThan": "9.5.1",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "9.5.1"
            }
          ]
        }
      ],
      "datePublic": "2026-09-30T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-287",
              "description": "CWE-287 Improper Authentication",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-30T20:14:40.084Z",
        "orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
        "shortName": "cisa-cg"
      },
      "references": [
        {
          "name": "url",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qjvp-25r3-rgx6"
        },
        {
          "name": "url",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"
        }
      ],
      "title": "Kiteworks Email Protection Gateway Improper Authentication",
      "x_generator": {
        "engine": "VINCE-NT 1.15.0+build.145"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
    "assignerShortName": "cisa-cg",
    "cveId": "CVE-2026-102128",
    "datePublished": "2026-09-30T20:14:40.084Z",
    "dateReserved": "2026-09-28T17:39:13.563Z",
    "dateUpdated": "2026-10-01T13:37:05.460Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation
Architecture and Design

Strategy: Libraries or Frameworks

Use an authentication framework or library such as the OWASP ESAPI Authentication feature.

CAPEC-114: Authentication Abuse

An attacker obtains unauthorized access to an application, service or device either through knowledge of the inherent weaknesses of an authentication mechanism, or by exploiting a flaw in the authentication scheme's implementation. In such an attack an authentication mechanism is functioning but a carefully controlled sequence of events causes the mechanism to grant access to the attacker.

CAPEC-115: Authentication Bypass

An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.

CAPEC-151: Identity Spoofing

Identity Spoofing refers to the action of assuming (i.e., taking on) the identity of some other entity (human or non-human) and then using that identity to accomplish a goal. An adversary may craft messages that appear to come from a different principle or use stolen / spoofed authentication credentials.

CAPEC-194: Fake the Source of Data

An adversary takes advantage of improper authentication to provide data or services under a falsified identity. The purpose of using the falsified identity may be to prevent traceability of the provided data or to assume the rights granted to another individual. One of the simplest forms of this attack would be the creation of an email message with a modified "From" field in order to appear that the message was sent from someone other than the actual sender. The root of the attack (in this case the email system) fails to properly authenticate the source and this results in the reader incorrectly performing the instructed action. Results of the attack vary depending on the details of the attack, but common results include privilege escalation, obfuscation of other attacks, and data corruption/manipulation.

CAPEC-22: Exploiting Trust in Client

An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.

CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data

This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.

CAPEC-593: Session Hijacking

This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.

CAPEC-633: Token Impersonation

An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary.

CAPEC-650: Upload a Web Shell to a Web Server

By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be executed remotely. This shell can have various capabilities, thereby acting as a "gateway" to the underlying web server. The shell might execute at the higher permission level of the web server, providing the ability the execute malicious code at elevated levels.

CAPEC-94: Adversary in the Middle (AiTM)

An adversary targets the communication between two components (typically client and server), in order to alter or obtain data from transactions. A general approach entails the adversary placing themself within the communication channel between the two components.