Common Weakness Enumeration

CWE-696

Allowed-with-Review

Incorrect Behavior Order

Abstraction: Class · Status: Incomplete

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

91 vulnerabilities reference this CWE, most recent first.

CVE-2026-103353 (GCVE-0-2026-103353)

Vulnerability from cvelistv5 – Published: 2026-10-01 10:48 – Updated: 2026-10-01 16:29 X_Open Source
VLAI
Title
WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability
Summary
Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.
SSVC
Exploitation: none Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 16:28 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
References
Impacted products
Vendor Product Version
WP ManageNinja LLC FluentForm Affected: 0 , ≤ 6.2.14 (custom)
Create a notification for this product.
Date Public
2026-10-01 10:48
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103353",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T16:28:27.334392Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T16:29:37.061Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://wordpress.org/plugins",
          "defaultStatus": "unaffected",
          "packageName": "fluentform",
          "product": "FluentForm",
          "vendor": "WP ManageNinja LLC",
          "versions": [
            {
              "changes": [
                {
                  "at": "6.2.15",
                  "status": "unaffected"
                }
              ],
              "lessThanOrEqual": "6.2.14",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "MYUNGYONG LEE | Patchstack Bug Bounty Program"
        }
      ],
      "datePublic": "2026-10-01T10:48:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.\u003cp\u003eThis issue affects FluentForm: from n/a through 6.2.14.\u003c/p\u003e"
            }
          ],
          "value": "Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-207",
          "descriptions": [
            {
              "lang": "en",
              "value": "Removing Important Client Functionality"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T10:48:43.686Z",
        "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "shortName": "Patchstack"
      },
      "references": [
        {
          "tags": [
            "vdb-entry"
          ],
          "url": "https://patchstack.com/database/wordpress/plugin/fluentform/vulnerability/wordpress-fluentform-plugin-6-2-14-broken-access-control-vulnerability?_s_id=cve"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Update the WordPress FluentForm plugin to the latest available version (at least 6.2.15)."
            }
          ],
          "value": "Update the WordPress FluentForm plugin to the latest available version (at least 6.2.15)."
        }
      ],
      "tags": [
        "x_open-source"
      ],
      "title": "WordPress FluentForm plugin \u003c= 6.2.14 - Broken Access Control vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
    "assignerShortName": "Patchstack",
    "cveId": "CVE-2026-103353",
    "datePublished": "2026-10-01T10:48:43.088Z",
    "dateReserved": "2026-09-30T12:43:33.094Z",
    "dateUpdated": "2026-10-01T16:29:37.061Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-103012 (GCVE-0-2026-103012)

Vulnerability from cvelistv5 – Published: 2026-09-30 11:30 – Updated: 2026-09-30 14:28
VLAI
Summary
Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later. Thank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:28 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
Impacted products
Vendor Product Version
Anthropic @anthropic-ai/claude-code Affected: 2.0.68 , < 2.1.260 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-103012",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-30T14:28:28.868892Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-30T14:28:45.094Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "@anthropic-ai/claude-code",
          "vendor": "Anthropic",
          "versions": [
            {
              "lessThan": "2.1.260",
              "status": "affected",
              "version": "2.0.68",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user\u0027s valid Claude Enterprise or Team sign-in when fetching the organization\u0027s server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization\u0027s server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes \u2014 while continuing to operate as the organization\u0027s account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.\n\nThank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "baseScore": 2,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-30T11:30:38.308Z",
        "orgId": "98a01053-8a31-4f6d-9aa9-252be161adc6",
        "shortName": "Anthropic"
      },
      "references": [
        {
          "url": "https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "98a01053-8a31-4f6d-9aa9-252be161adc6",
    "assignerShortName": "Anthropic",
    "cveId": "CVE-2026-103012",
    "datePublished": "2026-09-30T11:30:38.308Z",
    "dateReserved": "2026-09-29T21:06:44.918Z",
    "dateUpdated": "2026-09-30T14:28:45.094Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93330 (GCVE-0-2026-93330)

Vulnerability from cvelistv5 – Published: 2026-09-29 15:25 – Updated: 2026-09-29 15:40
VLAI
Summary
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 15:40 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
Impacted products
Vendor Product Version
Devolutions Server Affected: 0 , < 2026.3.7.0 (custom)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "NONE",
              "baseScore": 4.3,
              "baseSeverity": "MEDIUM",
              "confidentialityImpact": "LOW",
              "integrityImpact": "NONE",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-93330",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-29T15:40:47.793465Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-29T15:40:51.204Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Server",
          "vendor": "Devolutions",
          "versions": [
            {
              "lessThan": "2026.3.7.0",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset."
            }
          ],
          "value": "Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-29T15:25:16.942Z",
        "orgId": "bfee16bd-18e6-446c-9a65-f5b2e3d89c23",
        "shortName": "DEVOLUTIONS"
      },
      "references": [
        {
          "url": "https://devolutions.net/security/advisories/DEVO-2026-0034/"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "bfee16bd-18e6-446c-9a65-f5b2e3d89c23",
    "assignerShortName": "DEVOLUTIONS",
    "cveId": "CVE-2026-93330",
    "datePublished": "2026-09-29T15:25:16.942Z",
    "dateReserved": "2026-09-17T17:30:52.784Z",
    "dateUpdated": "2026-09-29T15:40:51.204Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-93304 (GCVE-0-2026-93304)

Vulnerability from cvelistv5 – Published: 2026-09-27 09:05 – Updated: 2026-09-29 16:43
VLAI
Title
(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange
Summary
A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client's own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 16:42 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
References
Impacted products
Vendor Product Version
wolfSSL wolfSSL Affected: 4.7.0 , ≤ 5.9.2 (semver)
Create a notification for this product.
Date Public
2026-09-26 12:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-93304",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-29T16:42:18.964567Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-29T16:43:16.572Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "wolfSSL",
          "vendor": "wolfSSL",
          "versions": [
            {
              "lessThanOrEqual": "5.9.2",
              "status": "affected",
              "version": "4.7.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Anthropic OSS program"
        }
      ],
      "datePublic": "2026-09-26T12:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server\u0027s Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client\u0027s own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK."
            }
          ],
          "value": "A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server\u0027s Finished against that same key. An out-of-order ChangeCipherSpec can therefore be used by an attacker to complete the handshake in place of the server and send data the client accepts as authentic. The client\u0027s own traffic still uses correctly derived keys, so the attacker cannot read it, and the genuine server never completes the handshake. DTLS 1.2 clients are exposed because a datagram read can deliver the out-of-order records on its own. TLS 1.2 clients are exposed when the application supplies received bytes with wolfSSL_inject() or enables read ahead. For certificate suites, the attacker must be in a man-in-the-middle position. For PSK (Pre Shared Key) connections, any fake server can succeed without knowing the PSK."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-27T09:05:37.132Z",
        "orgId": "50d2cd11-d01a-48ed-9441-5bfce9d63b27",
        "shortName": "wolfSSL"
      },
      "references": [
        {
          "url": "https://github.com/wolfSSL/wolfssl/pull/11458"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "(D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange",
      "x_generator": {
        "engine": "Vulnogram 1.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "50d2cd11-d01a-48ed-9441-5bfce9d63b27",
    "assignerShortName": "wolfSSL",
    "cveId": "CVE-2026-93304",
    "datePublished": "2026-09-27T09:05:37.132Z",
    "dateReserved": "2026-09-17T16:55:11.172Z",
    "dateUpdated": "2026-09-29T16:43:16.572Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-73446 (GCVE-0-2026-73446)

Vulnerability from cvelistv5 – Published: 2026-09-15 23:08 – Updated: 2026-09-16 19:34
VLAI
Title
Security Advisory 0160
Summary
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 19:34 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
References
Impacted products
Vendor Product Version
Arista Networks EOS Affected: 4.36.0 , ≤ 4.36.1F (custom)
Affected: 4.35.0 , ≤ 4.35.5M (custom)
Affected: 4.34.0 , ≤ 4.34.7.1M (custom)
Affected: 4.33.0 , ≤ 4.33.9M (custom)
Affected: 4.32.0 , < 4.33.0F (custom)
Affected: 4.31.0 , < 4.32.0F (custom)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-73446",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-16T19:34:09.117613Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-16T19:34:18.384Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "EOS",
          "vendor": "Arista Networks",
          "versions": [
            {
              "lessThanOrEqual": "4.36.1F",
              "status": "affected",
              "version": "4.36.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "4.35.5M",
              "status": "affected",
              "version": "4.35.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "4.34.7.1M",
              "status": "affected",
              "version": "4.34.0",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "4.33.9M",
              "status": "affected",
              "version": "4.33.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.33.0F",
              "status": "affected",
              "version": "4.32.0",
              "versionType": "custom"
            },
            {
              "lessThan": "4.32.0F",
              "status": "affected",
              "version": "4.31.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "configurations": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIS-IS must be enabled on a broadcast (LAN) interface AND there should be an active IS-IS adjacency on that interface:\u003c/p\u003e\u003cpre\u003eswitch(config-router-isis)#show active\nrouter isis 1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;net 49.0001.1111.1111.1001.00\nswitch(config-if-Et1)#show active\ninterface Ethernet1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;isis enable 1\u003cbr\u003e\u003cbr\u003e\u003cpre\u003eswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n\u003cbr\u003e\n\u0026nbsp;\u0026nbsp;Interface Ethernet1:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Index: 4 SNPA: 2:2:0:1:0:0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;MTU: 1497 Type: broadcast\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Supported address families: IPv4, IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Area proxy boundary is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;BFD IPv4 is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;BFD IPv6 is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Hello padding is enabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Level 1:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Metric: 10, Number of adjacencies: 1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;LAN-ID: 1111.1111.1001.04, Priority: 64\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;DIS: 1111.1111.1001, DIS priority: 64\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Authentication mode: None\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;TI-LFA protection is disabled for IPv4\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;TI-LFA protection is disabled for IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Adjacency 1111.1111.1002:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State: UP, Level: 1 Type: Level 1 IS\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Advertised hold time: 9\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Neighbor supported address families: IPv4, IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Address family match: Enabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;SNPA: 2:2:0:2:0:0, Priority: 64\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;IPv4 interface address: 10.0.0.2\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;IPv6 interface address: fe80::2:ff:fe02:0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Area addresses: 49.0001\u003c/pre\u003e\u003c/pre\u003e\u003cp\u003eIf IS-IS is not configured OR IS-IS is configured only on point-to-point interfaces, there is no exposure to this issue.\u003cbr\u003e\u003cbr\u003e\u003c/p\u003e\u003cpre\u003eswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n \n\u0026nbsp;\u0026nbsp;Interface Ethernet1:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Index: 4 SNPA: P2P\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;MTU: 1497 Type: point-to-point\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Supported address families: IPv4, IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Area proxy boundary is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;BFD IPv4 is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;BFD IPv6 is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Hello padding is enabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Local fast flooding is disabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Level 1:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Metric: 10, Number of adjacencies: 1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Link-ID: 04\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Authentication mode: None\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;TI-LFA protection is disabled for IPv4\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;TI-LFA protection is disabled for IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Adjacency 1111.1111.1002:\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State: UP, Level: 1 Type: Level 1 IS\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Advertised hold time: 30\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Neighbor supported address families: IPv4, IPv6\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Address family match: Enabled\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;IPv4 interface address: 1.0.0.2\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;IPv6 interface address: fe80::2:ff:fe02:0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Area addresses: 49.0001\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Peer fast flooding is disabled\u003cbr\u003e\u003c/pre\u003e"
            }
          ],
          "value": "IS-IS must be enabled on a broadcast (LAN) interface AND there should be an active IS-IS adjacency on that interface:\n\n\n\nswitch(config-router-isis)#show active\nrouter isis 1\n\u00a0\u00a0\u00a0net 49.0001.1111.1111.1001.00\nswitch(config-if-Et1)#show active\ninterface Ethernet1\n\u00a0\u00a0\u00a0isis enable 1\n\n\n\nswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n\n\n\u00a0\u00a0Interface Ethernet1:\n\u00a0\u00a0\u00a0\u00a0Index: 4 SNPA: 2:2:0:1:0:0\n\u00a0\u00a0\u00a0\u00a0MTU: 1497 Type: broadcast\n\u00a0\u00a0\u00a0\u00a0Supported address families: IPv4, IPv6\n\u00a0\u00a0\u00a0\u00a0Area proxy boundary is disabled\n\u00a0\u00a0\u00a0\u00a0BFD IPv4 is disabled\n\u00a0\u00a0\u00a0\u00a0BFD IPv6 is disabled\n\u00a0\u00a0\u00a0\u00a0Hello padding is enabled\n\u00a0\u00a0\u00a0\u00a0Level 1:\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Metric: 10, Number of adjacencies: 1\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0LAN-ID: 1111.1111.1001.04, Priority: 64\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0DIS: 1111.1111.1001, DIS priority: 64\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Authentication mode: None\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0TI-LFA protection is disabled for IPv4\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0TI-LFA protection is disabled for IPv6\n\u00a0\u00a0\u00a0\u00a0Adjacency 1111.1111.1002:\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State: UP, Level: 1 Type: Level 1 IS\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Advertised hold time: 9\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Neighbor supported address families: IPv4, IPv6\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Address family match: Enabled\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0SNPA: 2:2:0:2:0:0, Priority: 64\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0IPv4 interface address: 10.0.0.2\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0IPv6 interface address: fe80::2:ff:fe02:0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Area addresses: 49.0001\n\n\n\n\n\nIf IS-IS is not configured OR IS-IS is configured only on point-to-point interfaces, there is no exposure to this issue.\n\n\n\n\n\nswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n \n\u00a0\u00a0Interface Ethernet1:\n\u00a0\u00a0\u00a0\u00a0Index: 4 SNPA: P2P\n\u00a0\u00a0\u00a0\u00a0MTU: 1497 Type: point-to-point\n\u00a0\u00a0\u00a0\u00a0Supported address families: IPv4, IPv6\n\u00a0\u00a0\u00a0\u00a0Area proxy boundary is disabled\n\u00a0\u00a0\u00a0\u00a0BFD IPv4 is disabled\n\u00a0\u00a0\u00a0\u00a0BFD IPv6 is disabled\n\u00a0\u00a0\u00a0\u00a0Hello padding is enabled\n\u00a0\u00a0\u00a0\u00a0Local fast flooding is disabled\n\u00a0\u00a0\u00a0\u00a0Level 1:\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Metric: 10, Number of adjacencies: 1\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Link-ID: 04\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Authentication mode: None\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0TI-LFA protection is disabled for IPv4\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0TI-LFA protection is disabled for IPv6\n\u00a0\u00a0\u00a0\u00a0Adjacency 1111.1111.1002:\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State: UP, Level: 1 Type: Level 1 IS\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Advertised hold time: 30\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Neighbor supported address families: IPv4, IPv6\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Address family match: Enabled\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0IPv4 interface address: 1.0.0.2\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0IPv6 interface address: fe80::2:ff:fe02:0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Area addresses: 49.0001\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Peer fast flooding is disabled"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "This issue was discovered internally by Arista and the company is not aware of any malicious uses of these issues in customer networks."
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eOn affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.\u003c/p\u003e"
            }
          ],
          "value": "On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-272",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-272 Protocol Manipulation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "ADJACENT",
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696: Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-15T23:08:19.771Z",
        "orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
        "shortName": "Arista"
      },
      "references": [
        {
          "name": "Security Advisory 0160",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24716-security-advisory-0160"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eThe recommended resolution is to upgrade to a fixed software version.\u003c/p\u003e"
            }
          ],
          "value": "The recommended resolution is to upgrade to a fixed software version."
        }
      ],
      "source": {
        "advisory": "0160",
        "defects": [
          "BUG1840504"
        ],
        "discovery": "UNKNOWN"
      },
      "title": "Security Advisory 0160",
      "workarounds": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eNo workaround is available for this issue.\u003c/p\u003e"
            }
          ],
          "value": "No workaround is available for this issue."
        }
      ],
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
    "assignerShortName": "Arista",
    "cveId": "CVE-2026-73446",
    "datePublished": "2026-09-15T23:08:19.771Z",
    "dateReserved": "2026-08-12T16:42:47.920Z",
    "dateUpdated": "2026-09-16T19:34:18.384Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-68930 (GCVE-0-2026-68930)

Vulnerability from cvelistv5 – Published: 2026-08-03 15:34 – Updated: 2026-08-03 16:46
VLAI
Title
Russh: Channel-scoped server callbacks can be reached without an open channel
Summary
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.
SSVC
Exploitation: poc Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-03 16:43 UTC
CWE
  • CWE-666 - Operation on Resource in Wrong Phase of Lifetime
  • CWE-696 - Incorrect Behavior Order
  • CWE-863 - Incorrect Authorization
Impacted products
Vendor Product Version
Eugeny russh Affected: < 0.62.5
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-68930",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-03T16:43:29.958225Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-03T16:46:32.324Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "russh",
          "vendor": "Eugeny",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 0.62.5"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Russh is a Rust SSH client \u0026 server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-666",
              "description": "CWE-666: Operation on Resource in Wrong Phase of Lifetime",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696: Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-863",
              "description": "CWE-863: Incorrect Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-03T15:34:41.216Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg"
        },
        {
          "name": "https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171"
        },
        {
          "name": "https://github.com/Eugeny/russh/releases/tag/v0.62.5",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/Eugeny/russh/releases/tag/v0.62.5"
        }
      ],
      "source": {
        "advisory": "GHSA-m65r-rprj-r5rg",
        "discovery": "UNKNOWN"
      },
      "title": "Russh: Channel-scoped server callbacks can be reached without an open channel"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-68930",
    "datePublished": "2026-08-03T15:34:41.216Z",
    "dateReserved": "2026-07-31T21:49:24.927Z",
    "dateUpdated": "2026-08-03T16:46:32.324Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-67217 (GCVE-0-2026-67217)

Vulnerability from cvelistv5 – Published: 2026-07-29 13:32 – Updated: 2026-07-29 16:00
VLAI
Title
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
Summary
cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.
SSVC
Exploitation: poc Automatable: yes Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-29 14:45 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
Impacted products
Vendor Product Version
DaveGamble cJSON Affected: 0 , ≤ 1.7.19 (semver)
    cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-07-25 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-67217",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-29T14:45:50.377868Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-29T14:45:59.768Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "exploit"
            ],
            "url": "https://joshua.hu/cjson-json-parser-cve-vulnerabilities"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "cJSON",
          "vendor": "DaveGamble",
          "versions": [
            {
              "lessThanOrEqual": "1.7.19",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:davegamble:cjson:*:*:*:*:*:*:*:*",
                  "vulnerable": true
                }
              ],
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2026-07-25T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 6.9,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-29T16:00:27.693Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Security vulnerabilities in the cJSON JSON parser (Joshua Rogers)",
          "tags": [
            "exploit"
          ],
          "url": "https://joshua.hu/cjson-json-parser-cve-vulnerabilities"
        },
        {
          "name": "apply_patch delete-before-validate ordering (cJSON_Utils.c)",
          "tags": [
            "technical-description"
          ],
          "url": "https://github.com/DaveGamble/cJSON/blob/v1.7.19/cJSON_Utils.c#L887-L948"
        },
        {
          "name": "VulnCheck Advisory: cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/cjson-json-patch-non-atomic-application-destroys-data-before-validation"
        }
      ],
      "title": "cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation",
      "x_generator": {
        "engine": "vulncheck-endgame"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-67217",
    "datePublished": "2026-07-29T13:32:04.416Z",
    "dateReserved": "2026-07-28T19:20:19.157Z",
    "dateUpdated": "2026-07-29T16:00:27.693Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-65100 (GCVE-0-2026-65100)

Vulnerability from cvelistv5 – Published: 2026-07-29 09:06 – Updated: 2026-10-01 17:06
VLAI
Title
Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode
Summary
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-29 12:10 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
References
Impacted products
Vendor Product Version
Apache Software Foundation Apache Traffic Server Affected: 8.0.0 , ≤ 8.1.11 (semver)
Affected: 9.0.0 , ≤ 9.2.14 (semver)
Affected: 10.0.0 , ≤ 10.1.3 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-65100",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-29T12:10:15.907595Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-29T12:10:22.340Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Apache Traffic Server",
          "vendor": "Apache Software Foundation",
          "versions": [
            {
              "lessThanOrEqual": "8.1.11",
              "status": "affected",
              "version": "8.0.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "9.2.14",
              "status": "affected",
              "version": "9.0.0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "10.1.3",
              "status": "affected",
              "version": "10.0.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "Omkhar Arasaratnam"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "Apache Community"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eApache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection.\u003c/p\u003e\u003cp\u003eThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\u003c/p\u003e\u003cp\u003eUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.\u003c/p\u003e"
            }
          ],
          "value": "Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection.\n\n\n\nThis issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.\n\n\n\nUsers are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue."
        }
      ],
      "metrics": [
        {
          "other": {
            "content": {
              "text": "moderate"
            },
            "type": "Textual description of severity"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "LOW",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T17:06:34.984Z",
        "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
        "shortName": "apache"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode",
      "x_generator": {
        "engine": "scripts/cve_render.py"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
    "assignerShortName": "apache",
    "cveId": "CVE-2026-65100",
    "datePublished": "2026-07-29T09:06:17.226Z",
    "dateReserved": "2026-07-21T17:10:18.202Z",
    "dateUpdated": "2026-10-01T17:06:34.984Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-56355 (GCVE-0-2026-56355)

Vulnerability from cvelistv5 – Published: 2026-06-20 20:08 – Updated: 2026-06-22 17:21
VLAI
Summary
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-22 17:21 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
Impacted products
Vendor Product Version
GNU Savane Affected: 3.14 , ≤ 3.17 (custom)
    cpe:2.3:a:gnu:savane:*:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-56355",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-22T17:21:08.779367Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-22T17:21:17.681Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Savane",
          "vendor": "GNU",
          "versions": [
            {
              "lessThanOrEqual": "3.17",
              "status": "affected",
              "version": "3.14",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:gnu:savane:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "3.17",
                  "versionStartIncluding": "3.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-20T20:08:05.163Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n113"
        },
        {
          "url": "https://cgit.git.savannah.gnu.org/cgit/administration/savane.git/tree/frontend/php/file.php?h=release-3.17#n123"
        },
        {
          "url": "https://www.fsf.org/news/statement-regarding-gnu-savannah-security-reports"
        },
        {
          "url": "https://www.hacktron.ai"
        },
        {
          "url": "https://www.mallory.ai/stories/019ee445-bdd4-7775-93b5-a8faaf5c2eb7"
        },
        {
          "url": "https://news.ycombinator.com/item?id=48605220"
        }
      ],
      "x_generator": {
        "engine": "CVE-Request-form 0.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2026-56355",
    "datePublished": "2026-06-20T20:08:05.163Z",
    "dateReserved": "2026-06-20T20:08:04.762Z",
    "dateUpdated": "2026-06-22T17:21:17.681Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-49318 (GCVE-0-2026-49318)

Vulnerability from cvelistv5 – Published: 2026-05-29 13:18 – Updated: 2026-06-27 08:48
VLAI
Title
Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot
Summary
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window — for example via a separately tracked CAN bus-off technique — can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-05-29 14:07 UTC
CWE
  • CWE-696 - Incorrect Behavior Order
  • CWE-636 - Not Failing Securely ('Failing Open')
  • CWE-754 - Improper Check for Unusual or Exceptional Conditions
References
URL Tags
https://cwe.mitre.org/data/definitions/696.html technical-description
Impacted products
Vendor Product Version
Indian Motorcycle Scout Bobber + Tech Affected: 2025 (model-year)
Create a notification for this product.
Date Public
2026-05-29 15:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-49318",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-29T14:07:21.099266Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-29T14:07:27.548Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "modules": [
            "Infotainment / Digital Round"
          ],
          "platforms": [
            "OEM Motorcycle"
          ],
          "product": "Scout Bobber + Tech",
          "vendor": "Indian Motorcycle",
          "versions": [
            {
              "status": "affected",
              "version": "2025",
              "versionType": "model-year"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Scott Sheahan, Rustic Security LLC"
        }
      ],
      "datePublic": "2026-05-29T15:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eIncorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window \u2014 for example via a separately tracked CAN bus-off technique \u2014 can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation.\u003c/p\u003e"
            }
          ],
          "value": "Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an immobilizer is fitted; if no WCM messages are observed, it skips the PIN entry screen and shows the normal user interface. An attacker who silences the WCM during the boot window \u2014 for example via a separately tracked CAN bus-off technique \u2014 can present a fully unlocked Infotainment despite the PIN never being entered. Specific timing and protocol details have been withheld pending vendor remediation."
        }
      ],
      "impacts": [
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "Authentication Bypass"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "Leveraging Race Conditions"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "PHYSICAL",
            "availabilityImpact": "NONE",
            "baseScore": 2.4,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "PHYSICAL",
            "baseScore": 1,
            "baseSeverity": "LOW",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-696",
              "description": "CWE-696 Incorrect Behavior Order",
              "lang": "en",
              "type": "CWE"
            },
            {
              "cweId": "CWE-636",
              "description": "CWE-636 Not Failing Securely (\u0027Failing Open\u0027)",
              "lang": "en",
              "type": "CWE"
            },
            {
              "cweId": "CWE-754",
              "description": "CWE-754 Improper Check for Unusual or Exceptional Conditions",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-27T08:48:24.495Z",
        "orgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
        "shortName": "ASRG"
      },
      "references": [
        {
          "tags": [
            "technical-description"
          ],
          "url": "https://cwe.mitre.org/data/definitions/696.html"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eFail secure on WCM absence: if the Infotainment cannot positively identify a WCM via signed challenge-response with a per-boot nonce, default to a locked screen indicating WCM service required, rather than skipping the PIN entry.\u003c/p\u003e"
            }
          ],
          "value": "Fail secure on WCM absence: if the Infotainment cannot positively identify a WCM via signed challenge-response with a per-boot nonce, default to a locked screen indicating WCM service required, rather than skipping the PIN entry."
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "timeline": [
        {
          "lang": "en",
          "time": "2025-03-26T00:00:00.000Z",
          "value": "Reported to Indian Motorcycle by Rustic Security LLC (responsible disclosure)"
        }
      ],
      "title": "Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at boot",
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "c15abc07-96a9-4d11-a503-5d621bfe42ba",
    "assignerShortName": "ASRG",
    "cveId": "CVE-2026-49318",
    "datePublished": "2026-05-29T13:18:52.305Z",
    "dateReserved": "2026-05-29T07:26:43.198Z",
    "dateUpdated": "2026-06-27T08:48:24.495Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

No mitigation information available for this CWE.

CAPEC-463: Padding Oracle Crypto Attack

An adversary is able to efficiently decrypt data without knowing the decryption key if a target system leaks data on whether or not a padding error happened while decrypting the ciphertext. A target system that leaks this type of information becomes the padding oracle and an adversary is able to make use of that oracle to efficiently decrypt data without knowing the decryption key by issuing on average 128*b calls to the padding oracle (where b is the number of bytes in the ciphertext block). In addition to performing decryption, an adversary is also able to produce valid ciphertexts (i.e., perform encryption) by using the padding oracle, all without knowing the encryption key.