CWE-287
DiscouragedImproper Authentication
Abstraction: Class · Status: Draft
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
6772 vulnerabilities reference this CWE, most recent first.
CVE-2026-100886 (GCVE-0-2026-100886)
Vulnerability from cvelistv5 – Published: 2026-09-27 23:00 – Updated: 2026-09-28 13:14- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410835 | vdb-entry |
| https://vuldb.com/vuln/410835/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100886 | third-party-advisory |
| https://vuldb.com/submit/916434 | third-party-advisory |
| https://github.com/heapframe/seetong-ts81xxd3x-rce | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Seetong | T8108 |
Affected:
4.6.1.4-build202604241011
cpe:2.3:a:seetong:t8108:*:*:*:*:*:*:*:* |
|
| Seetong | T8108P |
Affected:
4.6.1.4-build202604241011
cpe:2.3:a:seetong:t8108p:*:*:*:*:*:*:*:* |
|
| Seetong | T8116 |
Affected:
4.6.1.4-build202604241011
cpe:2.3:a:seetong:t8116:*:*:*:*:*:*:*:* |
|
| Seetong | T8232 |
Affected:
4.6.1.4-build202604241011
cpe:2.3:a:seetong:t8232:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100886",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:13:55.312968Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:14:08.318Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:seetong:t8108:*:*:*:*:*:*:*:*"
],
"modules": [
"Debug Service"
],
"product": "T8108",
"vendor": "Seetong",
"versions": [
{
"status": "affected",
"version": "4.6.1.4-build202604241011"
}
]
},
{
"cpes": [
"cpe:2.3:a:seetong:t8108p:*:*:*:*:*:*:*:*"
],
"modules": [
"Debug Service"
],
"product": "T8108P",
"vendor": "Seetong",
"versions": [
{
"status": "affected",
"version": "4.6.1.4-build202604241011"
}
]
},
{
"cpes": [
"cpe:2.3:a:seetong:t8116:*:*:*:*:*:*:*:*"
],
"modules": [
"Debug Service"
],
"product": "T8116",
"vendor": "Seetong",
"versions": [
{
"status": "affected",
"version": "4.6.1.4-build202604241011"
}
]
},
{
"cpes": [
"cpe:2.3:a:seetong:t8232:*:*:*:*:*:*:*:*"
],
"modules": [
"Debug Service"
],
"product": "T8232",
"vendor": "Seetong",
"versions": [
{
"status": "affected",
"version": "4.6.1.4-build202604241011"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "axjp"
},
{
"lang": "en",
"type": "reporter",
"value": "axjp (VulDB User)"
},
{
"lang": "en",
"type": "analyst",
"value": "axjp (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:W/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 10,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:W/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 10,
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:W/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T23:00:09.011Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410835 | Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410835"
},
{
"name": "VDB-410835 | CTI Indicators (IOB, IOC)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410835/cti"
},
{
"name": "CVE-2026-100886 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100886"
},
{
"name": "Submit #916434 | Seetong (Shenzhen Topsee Technology) iDVR/NVR platform (ts81xxd3x); shipped in Fullward T8108/T8108P/T8116/T8232 and Topsee-branded NVRs v4.6.1.4-build202604241011 Missing Authentication for Critical Function",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/916434"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/heapframe/seetong-ts81xxd3x-rce"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T16:22:31.000Z",
"value": "VulDB entry last update"
}
],
"title": "Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100886",
"datePublished": "2026-09-27T23:00:09.011Z",
"dateReserved": "2026-09-27T07:30:32.503Z",
"dateUpdated": "2026-09-28T13:14:08.318Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100876 (GCVE-0-2026-100876)
Vulnerability from cvelistv5 – Published: 2026-09-27 19:45 – Updated: 2026-09-30 22:09| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410806 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410806/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100876 | third-party-advisory |
| https://vuldb.com/submit/915442 | third-party-advisory |
| https://github.com/rmsbpro/Advisory/blob/main/bro… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| mathurvishal | CloudClassroom-PHP-Project |
Affected:
5dadec098bfbbf3300d60c3494db3fb95b66e7be
cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100876",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T22:08:18.124649Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T22:09:00.964Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/rmsbpro/Advisory/blob/main/broken-role-segregation.md"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*"
],
"product": "CloudClassroom-PHP-Project",
"vendor": "mathurvishal",
"versions": [
{
"status": "affected",
"version": "5dadec098bfbbf3300d60c3494db3fb95b66e7be"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "rmsbpro (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T19:45:08.814Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410806 | mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410806"
},
{
"name": "VDB-410806 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410806/cti"
},
{
"name": "CVE-2026-100876 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100876"
},
{
"name": "Submit #915442 | https://github.com/mathurvishal/CloudClassroom-PHP-Project CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be Missing Authorization",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/915442"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/rmsbpro/Advisory/blob/main/broken-role-segregation.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T05:33:08.000Z",
"value": "VulDB entry last update"
}
],
"title": "mathurvishal CloudClassroom-PHP-Project loginlinkstudent.php missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100876",
"datePublished": "2026-09-27T19:45:08.814Z",
"dateReserved": "2026-09-27T03:27:47.296Z",
"dateUpdated": "2026-09-30T22:09:00.964Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100871 (GCVE-0-2026-100871)
Vulnerability from cvelistv5 – Published: 2026-09-27 13:09 – Updated: 2026-09-30 15:27- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/Sylius/Sylius/security/advisor… | vendor-advisory |
| https://github.com/Sylius/Sylius/pull/19213 | patchissue-tracking |
| https://github.com/Sylius/Sylius/commit/cdfb672a4… | patch |
| https://github.com/Sylius/Sylius/releases/tag/v2.2.9 | release-notes |
| https://github.com/Sylius/Sylius | product |
| https://www.vulncheck.com/advisories/sylius-befor… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Sylius | Sylius |
Affected:
1.11.0 , < 1.12.25
(semver)
Affected: 1.13.0 , < 1.13.17 (semver) Affected: 1.14.0 , < 1.14.20 (semver) Affected: 2.0.0 , < 2.1.16 (semver) Affected: 2.2.0 , < 2.2.9 (semver) cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100871",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:27:17.794970Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:27:27.292Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://packagist.org",
"defaultStatus": "unaffected",
"packageName": "sylius/sylius",
"packageURL": "pkg:composer/sylius/sylius",
"product": "Sylius",
"vendor": "Sylius",
"versions": [
{
"lessThan": "1.12.25",
"status": "affected",
"version": "1.11.0",
"versionType": "semver"
},
{
"lessThan": "1.13.17",
"status": "affected",
"version": "1.13.0",
"versionType": "semver"
},
{
"lessThan": "1.14.20",
"status": "affected",
"version": "1.14.0",
"versionType": "semver"
},
{
"lessThan": "2.1.16",
"status": "affected",
"version": "2.0.0",
"versionType": "semver"
},
{
"lessThan": "2.2.9",
"status": "affected",
"version": "2.2.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.12.25",
"versionStartIncluding": "1.11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.13.17",
"versionStartIncluding": "1.13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*",
"versionEndExcluding": "1.14.20",
"versionStartIncluding": "1.14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.1.16",
"versionStartIncluding": "2.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.2.9",
"versionStartIncluding": "2.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator\u0027s email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T14:29:45.532Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-f6mx-qxjc-55xf)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-f6mx-qxjc-55xf"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/Sylius/Sylius/pull/19213"
},
{
"tags": [
"patch"
],
"url": "https://github.com/Sylius/Sylius/commit/cdfb672a4d174eb2c73159b25cf5b5f44088f45c"
},
{
"name": "Sylius v2.2.9 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/Sylius/Sylius/releases/tag/v2.2.9"
},
{
"tags": [
"product"
],
"url": "https://github.com/Sylius/Sylius"
},
{
"name": "VulnCheck Advisory: Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/sylius-before-1.12.25-1.13.17-1.14.20-2.1.16-and-2.2.9-jwt-audience-confusion-allows-admin-api-authentication"
}
],
"title": "Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API Authentication",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100871",
"datePublished": "2026-09-27T13:09:55.386Z",
"dateReserved": "2026-09-27T00:20:54.408Z",
"dateUpdated": "2026-09-30T15:27:27.292Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100746 (GCVE-0-2026-100746)
Vulnerability from cvelistv5 – Published: 2026-09-27 03:30 – Updated: 2026-09-28 13:48 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410617 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410617/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-100746 | third-party-advisory |
| https://vuldb.com/submit/897404 | third-party-advisory |
| https://github.com/lakshayyverma/CVE-Discovery/bl… | exploit |
| https://github.com/coollabsio/coolify/pull/10362 | issue-trackingpatch |
| https://github.com/coollabsio/coolify/commit/fc89… | patch |
| https://github.com/coollabsio/coolify/releases/ta… | patch |
| https://github.com/coollabsio/coolify/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| coollabsio | Coolify |
Affected:
4.0
Affected: 4.1.0 Unaffected: 4.1.1 cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100746",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T13:47:48.281718Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T13:48:00.442Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:coollabsio:coolify:*:*:*:*:*:*:*:*"
],
"modules": [
"GitHub App Setup Handler"
],
"product": "Coolify",
"vendor": "coollabsio",
"versions": [
{
"status": "affected",
"version": "4.0"
},
{
"status": "affected",
"version": "4.1.0"
},
{
"status": "unaffected",
"version": "4.1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "lakshay12311 (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the argument state results in missing authentication. The attack can be executed remotely. The exploit has been made public and could be used. Upgrading to version 4.1.1 mitigates this issue. The patch is identified as fc89e357feed5180ed1ab5eb9cb330578f025539. The affected component should be upgraded."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T03:30:18.973Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410617 | coollabsio Coolify GitHub App Setup redirect missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410617"
},
{
"name": "VDB-410617 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410617/cti"
},
{
"name": "CVE-2026-100746 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-100746"
},
{
"name": "Submit #897404 | coollabsio Coolify 4.1.1 Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/897404"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/lakshayyverma/CVE-Discovery/blob/main/coolify-unauth-secret-overwrite-github-app-redirect.7z"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/coollabsio/coolify/pull/10362"
},
{
"tags": [
"patch"
],
"url": "https://github.com/coollabsio/coolify/commit/fc89e357feed5180ed1ab5eb9cb330578f025539"
},
{
"tags": [
"patch"
],
"url": "https://github.com/coollabsio/coolify/releases/tag/v4.1.1"
},
{
"tags": [
"product"
],
"url": "https://github.com/coollabsio/coolify/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-26T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-26T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-26T15:37:51.000Z",
"value": "VulDB entry last update"
}
],
"title": "coollabsio Coolify GitHub App Setup redirect missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-100746",
"datePublished": "2026-09-27T03:30:18.973Z",
"dateReserved": "2026-09-26T13:32:40.829Z",
"dateUpdated": "2026-09-28T13:48:00.442Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100709 (GCVE-0-2026-100709)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:24 – Updated: 2026-09-26 23:08- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/froxlor/froxlor/security/advis… | vendor-advisory |
| https://www.vulncheck.com/advisories/froxlor-befo… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100709",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-26T23:08:11.816656Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T23:08:21.420Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "froxlor",
"vendor": "froxlor",
"versions": [
{
"lessThan": "2.3.12",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.3.12",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "RobinMoschini"
}
],
"datePublic": "2026-09-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID also matches an administrator with the same ID. An attacker who controls a customer account with a colliding ID, holds a valid remembered-2FA cookie for it, and already knows the target administrator\u0027s password can bypass the administrator\u0027s TOTP second factor and obtain an authenticated administrator session. This is a second-factor bypass only; it does not defeat password authentication. Fixed in 2.3.12."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:24:02.908Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-9fq7-9w8p-c3qh)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/froxlor/froxlor/security/advisories/GHSA-9fq7-9w8p-c3qh"
},
{
"name": "VulnCheck Advisory: Froxlor before 2.3.12 2FA Bypass via Namespace Confusion",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/froxlor-before-2.3.12-2fa-bypass-via-namespace-confusion"
}
],
"title": "Froxlor before 2.3.12 2FA Bypass via Namespace Confusion",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100709",
"datePublished": "2026-09-26T13:24:02.908Z",
"dateReserved": "2026-09-26T02:40:23.372Z",
"dateUpdated": "2026-09-26T23:08:21.420Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100684 (GCVE-0-2026-100684)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:23 – Updated: 2026-09-28 16:36- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/Budibase/budibase/security/adv… | vendor-advisory |
| https://www.vulncheck.com/advisories/budibase-ser… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100684",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T16:36:13.282180Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T16:36:39.716Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Budibase/budibase/security/advisories/GHSA-35ch-57g2-3g98"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/budibase/server",
"product": "server",
"vendor": "budibase",
"versions": [
{
"lessThan": "3.45.0",
"status": "affected",
"version": "3.41.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "3.45.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "manus-use"
}
],
"datePublic": "2026-09-10T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone \u2014 without validating an invite code and without an email_verified check (the email_verified gate protects only the existing-account lookup). An attacker who can register at an IdP that the tenant trusts for OIDC and assert a victim\u0027s invited email address (even with email_verified=false) claims the pending invite and inherits all of its granted privileges, including builder and admin.global, with no admin exclusion. This results in takeover of the invited principal and, for admin invites, full tenant compromise (access to all apps, datasources including production credentials, and automations); the invite is consumed, denying onboarding to the legitimate invitee."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:23:45.225Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-35ch-57g2-3g98)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/Budibase/budibase/security/advisories/GHSA-35ch-57g2-3g98"
},
{
"name": "VulnCheck Advisory: Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/budibase-server-3.41.0-before-3.45.0-authentication-bypass-via-oidc"
}
],
"title": "Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100684",
"datePublished": "2026-09-26T13:23:45.225Z",
"dateReserved": "2026-09-26T02:36:51.810Z",
"dateUpdated": "2026-09-28T16:36:39.716Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100607 (GCVE-0-2026-100607)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-28 17:07- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/adv… | vendor-advisory |
| https://www.vulncheck.com/advisories/flowise-thro… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100607",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T17:07:19.926137Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T17:07:58.552Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-cffm-583c-vffr"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/flowise",
"product": "Flowise",
"vendor": "FlowiseAI",
"versions": [
{
"lessThanOrEqual": "3.1.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.1.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "amwhoi"
}
],
"datePublic": "2026-09-10T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attackers can gain complete account access including chatflows, credentials, and API keys by authenticating through a different SSO provider or local password than the victim\u0027s original registration method."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:22:50.537Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-cffm-583c-vffr)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-cffm-583c-vffr"
},
{
"name": "VulnCheck Advisory: Flowise through 3.1.4 Authentication Bypass via Email-Only SSO",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/flowise-through-3.1.4-authentication-bypass-via-email-only-sso"
}
],
"title": "Flowise through 3.1.4 Authentication Bypass via Email-Only SSO",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100607",
"datePublished": "2026-09-26T13:22:50.537Z",
"dateReserved": "2026-09-26T02:30:34.352Z",
"dateUpdated": "2026-09-28T17:07:58.552Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-100606 (GCVE-0-2026-100606)
Vulnerability from cvelistv5 – Published: 2026-09-26 13:22 – Updated: 2026-09-28 19:10- CWE-287 - Improper Authentication
| URL | Tags |
|---|---|
| https://github.com/FlowiseAI/Flowise/security/adv… | vendor-advisory |
| https://www.vulncheck.com/advisories/flowise-thro… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-100606",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T19:08:17.212056Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T19:10:36.679Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vf3j-89vf-r697"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/flowise",
"product": "Flowise",
"vendor": "FlowiseAI",
"versions": [
{
"lessThanOrEqual": "3.1.4",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.1.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "amwhoi"
}
],
"datePublic": "2026-09-10T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database \u2014 including the server-stored single-use invitation tempToken \u2014 into the data passed to AccountService.register(). The register handler\u0027s token lookup, email match, and expiry checks therefore pass trivially against the server\u0027s own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee\u0027s email address as the email claim can take over that invitation and obtain the invited user\u0027s access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-26T13:22:49.835Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-vf3j-89vf-r697)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vf3j-89vf-r697"
},
{
"name": "VulnCheck Advisory: Flowise through 3.1.4 Authentication Bypass via SSO Email Match",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/flowise-through-3.1.4-authentication-bypass-via-sso-email-match"
}
],
"title": "Flowise through 3.1.4 Authentication Bypass via SSO Email Match",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-100606",
"datePublished": "2026-09-26T13:22:49.835Z",
"dateReserved": "2026-09-26T02:30:34.352Z",
"dateUpdated": "2026-09-28T19:10:36.679Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97879 (GCVE-0-2026-97879)
Vulnerability from cvelistv5 – Published: 2026-09-25 16:45 – Updated: 2026-09-25 17:02| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409900 | vdb-entry |
| https://vuldb.com/vuln/409900/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-97879 | third-party-advisory |
| https://vuldb.com/submit/913577 | third-party-advisory |
| https://github.com/ArrestX/startraining-advisorie… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| zhistaredu | StarTraining |
Affected:
3.8.0
Affected: 3.8.1 cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97879",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T17:02:11.698235Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T17:02:21.977Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*"
],
"modules": [
"api-docs Endpoint"
],
"product": "StarTraining",
"vendor": "zhistaredu",
"versions": [
{
"status": "affected",
"version": "3.8.0"
},
{
"status": "affected",
"version": "3.8.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Vseen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T16:45:14.557Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409900 | zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/409900"
},
{
"name": "VDB-409900 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409900/cti"
},
{
"name": "CVE-2026-97879 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-97879"
},
{
"name": "Submit #913577 | zhistaredu StarTraining 3.8.1 Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/913577"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-003-swagger-api-docs-unauth.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-25T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-25T11:02:08.000Z",
"value": "VulDB entry last update"
}
],
"title": "zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-97879",
"datePublished": "2026-09-25T16:45:14.557Z",
"dateReserved": "2026-09-25T08:56:50.919Z",
"dateUpdated": "2026-09-25T17:02:21.977Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97878 (GCVE-0-2026-97878)
Vulnerability from cvelistv5 – Published: 2026-09-25 16:30 – Updated: 2026-09-25 17:48| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409899 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409899/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-97878 | third-party-advisory |
| https://vuldb.com/submit/913576 | third-party-advisory |
| https://github.com/ArrestX/startraining-advisorie… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| zhistaredu | StarTraining |
Affected:
3.8.0
Affected: 3.8.1 cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97878",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T17:48:23.246522Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T17:48:41.038Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*"
],
"modules": [
"Druid Console"
],
"product": "StarTraining",
"vendor": "zhistaredu",
"versions": [
{
"status": "affected",
"version": "3.8.0"
},
{
"status": "affected",
"version": "3.8.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Vseen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T16:30:07.246Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409899 | zhistaredu StarTraining Druid Console index.html anonymous missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409899"
},
{
"name": "VDB-409899 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409899/cti"
},
{
"name": "CVE-2026-97878 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-97878"
},
{
"name": "Submit #913576 | zhistaredu StarTraining 3.8.1 Use of Default Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/913576"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-002-druid-console-unauth.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-25T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-25T11:02:04.000Z",
"value": "VulDB entry last update"
}
],
"title": "zhistaredu StarTraining Druid Console index.html anonymous missing authentication",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-97878",
"datePublished": "2026-09-25T16:30:07.246Z",
"dateReserved": "2026-09-25T08:56:47.170Z",
"dateUpdated": "2026-09-25T17:48:41.038Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Strategy: Libraries or Frameworks
Use an authentication framework or library such as the OWASP ESAPI Authentication feature.
CAPEC-114: Authentication Abuse
An attacker obtains unauthorized access to an application, service or device either through knowledge of the inherent weaknesses of an authentication mechanism, or by exploiting a flaw in the authentication scheme's implementation. In such an attack an authentication mechanism is functioning but a carefully controlled sequence of events causes the mechanism to grant access to the attacker.
CAPEC-115: Authentication Bypass
An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.
CAPEC-151: Identity Spoofing
Identity Spoofing refers to the action of assuming (i.e., taking on) the identity of some other entity (human or non-human) and then using that identity to accomplish a goal. An adversary may craft messages that appear to come from a different principle or use stolen / spoofed authentication credentials.
CAPEC-194: Fake the Source of Data
An adversary takes advantage of improper authentication to provide data or services under a falsified identity. The purpose of using the falsified identity may be to prevent traceability of the provided data or to assume the rights granted to another individual. One of the simplest forms of this attack would be the creation of an email message with a modified "From" field in order to appear that the message was sent from someone other than the actual sender. The root of the attack (in this case the email system) fails to properly authenticate the source and this results in the reader incorrectly performing the instructed action. Results of the attack vary depending on the details of the attack, but common results include privilege escalation, obfuscation of other attacks, and data corruption/manipulation.
CAPEC-22: Exploiting Trust in Client
An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.
CAPEC-57: Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
This attack utilizes a REST(REpresentational State Transfer)-style applications' trust in the system resources and environment to obtain sensitive data once SSL is terminated.
CAPEC-593: Session Hijacking
This type of attack involves an adversary that exploits weaknesses in an application's use of sessions in performing authentication. The adversary is able to steal or manipulate an active session and use it to gain unathorized access to the application.
CAPEC-633: Token Impersonation
An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary.
CAPEC-650: Upload a Web Shell to a Web Server
By exploiting insufficient permissions, it is possible to upload a web shell to a web server in such a way that it can be executed remotely. This shell can have various capabilities, thereby acting as a "gateway" to the underlying web server. The shell might execute at the higher permission level of the web server, providing the ability the execute malicious code at elevated levels.
CAPEC-94: Adversary in the Middle (AiTM)
An adversary targets the communication between two components (typically client and server), in order to alter or obtain data from transactions. A general approach entails the adversary placing themself within the communication channel between the two components.