CWE-749
AllowedExposed Dangerous Method or Function
Abstraction: Base · Status: Incomplete
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
347 vulnerabilities reference this CWE, most recent first.
CVE-2026-102667 (GCVE-0-2026-102667)
Vulnerability from cvelistv5 – Published: 2026-10-01 19:42 – Updated: 2026-10-01 19:42- CWE-749 - Exposed Dangerous Method or Function
| URL | Tags |
|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-1026667 | vdb-entry |
| Vendor | Product | Version | |
|---|---|---|---|
| Joyland | Joyland.ai |
Affected:
*
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "Joyland.ai",
"vendor": "Joyland",
"versions": [
{
"status": "affected",
"version": "*"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Vincent C., CodeVispera"
}
],
"datePublic": "2026-10-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex \u0027stream\u0027 module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "ADJACENT",
"baseScore": 9,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-102667",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T20:45:34.916197Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749 Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:42:24.250Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-275-03.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-1026667"
}
],
"title": "Joyland AI WebView command injection"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-102667",
"datePublished": "2026-10-01T19:42:24.250Z",
"dateReserved": "2026-09-29T16:07:07.813Z",
"dateUpdated": "2026-10-01T19:42:24.250Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96430 (GCVE-0-2026-96430)
Vulnerability from cvelistv5 – Published: 2026-09-29 08:20 – Updated: 2026-09-29 15:56- CWE-749 - Exposed dangerous method or function
| URL | Tags |
|---|---|
| https://zuso.ai/cve-advisory/advisory | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Flowring Technology Corp | Agentflow 4.0 |
Affected:
0 , < 2026/08/28
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96430",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T15:55:51.770778Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T15:56:09.548Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Agentflow 4.0",
"vendor": "Flowring Technology Corp",
"versions": [
{
"lessThan": "2026/08/28",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"datePublic": "2026-09-29T04:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Exposed Dangerous Method or Function in the\n/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote\nauthenticated users to execute arbitrary SQL commands via the sql parameter."
}
],
"value": "Exposed Dangerous Method or Function in the\n/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote\nauthenticated users to execute arbitrary SQL commands via the sql parameter."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749 Exposed dangerous method or function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T08:20:57.253Z",
"orgId": "256c161b-b921-402b-8c3b-c6c9c14d5d88",
"shortName": "ZUSO ART"
},
"references": [
{
"tags": [
"third-party-advisory"
],
"url": "https://zuso.ai/cve-advisory/advisory"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Flowring Agentflow 4.0 - Exposed Dangerous Method or Function",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "256c161b-b921-402b-8c3b-c6c9c14d5d88",
"assignerShortName": "ZUSO ART",
"cveId": "CVE-2026-96430",
"datePublished": "2026-09-29T08:20:57.253Z",
"dateReserved": "2026-09-23T06:38:54.186Z",
"dateUpdated": "2026-09-29T15:56:09.548Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92612 (GCVE-0-2026-92612)
Vulnerability from cvelistv5 – Published: 2026-09-21 10:47 – Updated: 2026-09-21 11:09| Vendor | Product | Version | |
|---|---|---|---|
| Eclipse Foundation | Eclipse iceoryx™ |
Affected:
0.8.1 , ≤ *
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92612",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T11:08:54.184278Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T11:09:34.304Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/eclipse-iceoryx/iceoryx2/security/advisories/GHSA-8mq4-3mwq-qvg6"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Eclipse iceoryx\u2122",
"vendor": "Eclipse Foundation",
"versions": [
{
"lessThanOrEqual": "*",
"status": "affected",
"version": "0.8.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "https://github.com/hudson-oai"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid \u0026amp;str and trigger undefined behavior using entirely safe Rust.\u003c/p\u003e"
}
],
"value": "In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid \u0026str and trigger undefined behavior using entirely safe Rust."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 1,
"baseSeverity": "LOW",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T10:47:02.731Z",
"orgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
"shortName": "eclipse"
},
"references": [
{
"url": "https://github.com/eclipse-iceoryx/iceoryx2/security/advisories/GHSA-8mq4-3mwq-qvg6"
},
{
"url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/307"
},
{
"url": "https://github.com/eclipse-iceoryx/iceoryx2/releases/tag/v0.10.0"
},
{
"url": "https://crates.io/crates/iceoryx2-bb-container/0.10.0"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "e51fbebd-6053-4e49-959f-1b94eeb69a2c",
"assignerShortName": "eclipse",
"cveId": "CVE-2026-92612",
"datePublished": "2026-09-21T10:47:02.731Z",
"dateReserved": "2026-09-16T14:12:26.764Z",
"dateUpdated": "2026-09-21T11:09:34.304Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89139 (GCVE-0-2026-89139)
Vulnerability from cvelistv5 – Published: 2026-09-21 11:41 – Updated: 2026-09-21 15:24| URL | Tags |
|---|---|
| https://github.com/temporalio/temporal/releases/t… | release-notes |
| https://github.com/temporalio/temporal/releases/t… | release-notes |
| https://github.com/temporalio/temporal-auto-scale… | patch |
| https://github.com/temporalio/temporal/pull/12021 | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| Temporal Technologies, Inc. | Temporal Server |
Affected:
1.31.0 , < 1.31.3
(semver)
cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89139",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:24:29.098568Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:24:46.549Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://pkg.go.dev",
"cpes": [
"cpe:2.3:a:temporal:temporal:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"packageName": "go.temporal.io/server",
"product": "Temporal Server",
"repo": "https://github.com/temporalio/temporal",
"vendor": "Temporal Technologies, Inc.",
"versions": [
{
"lessThan": "1.31.3",
"status": "affected",
"version": "1.31.0",
"versionType": "semver"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eExploitation requires all of the following at once. The deployment runs an affected Temporal Server release with the Worker Service enabled, which is the default service set, so a stock deployment satisfies this. Authorization is configured through an authorizer and a claim mapper; without it every caller already holds unrestricted access to every namespace and there is no namespace boundary to cross. The caller holds a write role in some namespace, which is what the frontend requires to create a worker deployment version or to update a worker deployment version\u0027s compute configuration. A worker deployment is already registered in that namespace, because the create call updates an existing worker deployment rather than starting one; registering a worker deployment requires the same namespace write role the rest of the path already requires, so this adds a step without raising the privilege needed. No feature flag has to be enabled by the operator: system.enableDeploymentVersions defaults to true, the per-namespace Worker Controller component is enabled unconditionally, and the compute provider allowlist defaults to permitting every registered provider. The provider wraps the command it runs in the timeout utility, which must resolve on the host\u0027s PATH; the base image used for the official container images supplies it.\u003c/p\u003e"
}
],
"value": "Exploitation requires all of the following at once. The deployment runs an affected Temporal Server release with the Worker Service enabled, which is the default service set, so a stock deployment satisfies this. Authorization is configured through an authorizer and a claim mapper; without it every caller already holds unrestricted access to every namespace and there is no namespace boundary to cross. The caller holds a write role in some namespace, which is what the frontend requires to create a worker deployment version or to update a worker deployment version\u0027s compute configuration. A worker deployment is already registered in that namespace, because the create call updates an existing worker deployment rather than starting one; registering a worker deployment requires the same namespace write role the rest of the path already requires, so this adds a step without raising the privilege needed. No feature flag has to be enabled by the operator: system.enableDeploymentVersions defaults to true, the per-namespace Worker Controller component is enabled unconditionally, and the compute provider allowlist defaults to permitting every registered provider. The provider wraps the command it runs in the timeout utility, which must resolve on the host\u0027s PATH; the base image used for the official container images supplies it."
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Reported internally at Temporal Technologies, Inc."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eTemporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are taken from the compute provider configuration supplied in the caller\u0027s request rather than from operator configuration. An authenticated caller holding only a write role in a single namespace can therefore configure a worker deployment version so that the Worker Service executes a command of the caller\u0027s choosing on its own host, under the account the server process runs as. Execution is immediate rather than deferred: the configuration handler invokes every provider using the invoke strategy directly after validating the submitted specification, so no scaling decision, task arrival, or unusual request sequence is required. Because the Worker Service process holds the persistence credentials for every namespace in the cluster and the cluster\u0027s TLS material, the consequence reaches beyond the caller\u0027s namespace to the cluster as a whole. The provider is present in the official temporal-server binaries and container images for the affected releases. The only control that can keep it unreachable is the compute provider allowlist, the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled, and that control does not deny by default: its default value is an unset list, and the allowlist check is skipped entirely when the value is unset, so every registered compute provider is permitted, this one included. To determine whether a deployment is affected, check the following together. The deployed Temporal Server version is 1.31.0 or later and earlier than 1.31.3. The Worker Service is running, which it is in the default service set and therefore in a stock deployment. The effective per-namespace value of workercontroller.compute_providers.enabled is either unset or contains subprocess. And authorization is configured, meaning a real authorizer and claim mapper are in place; a deployment running with no authorizer already grants every caller unrestricted access to every namespace, so it has no namespace boundary for this to cross. Note that the separate per-namespace dynamic configuration setting workercontroller.enabled does not gate the affected path. It defaults to false, and a deployment that has never set it in any namespace is still affected, which was confirmed by running an affected release with no value for that setting present anywhere in dynamic configuration. To look for a compute configuration that is already attached, call DescribeWorkerDeploymentVersion for each worker deployment version in each namespace and check whether any scaling group\u0027s compute provider type is subprocess.\u003c/p\u003e"
}
],
"value": "Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Worker Service. The program name and the argument vector that provider executes are taken from the compute provider configuration supplied in the caller\u0027s request rather than from operator configuration. An authenticated caller holding only a write role in a single namespace can therefore configure a worker deployment version so that the Worker Service executes a command of the caller\u0027s choosing on its own host, under the account the server process runs as. Execution is immediate rather than deferred: the configuration handler invokes every provider using the invoke strategy directly after validating the submitted specification, so no scaling decision, task arrival, or unusual request sequence is required. Because the Worker Service process holds the persistence credentials for every namespace in the cluster and the cluster\u0027s TLS material, the consequence reaches beyond the caller\u0027s namespace to the cluster as a whole. The provider is present in the official temporal-server binaries and container images for the affected releases. The only control that can keep it unreachable is the compute provider allowlist, the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled, and that control does not deny by default: its default value is an unset list, and the allowlist check is skipped entirely when the value is unset, so every registered compute provider is permitted, this one included. To determine whether a deployment is affected, check the following together. The deployed Temporal Server version is 1.31.0 or later and earlier than 1.31.3. The Worker Service is running, which it is in the default service set and therefore in a stock deployment. The effective per-namespace value of workercontroller.compute_providers.enabled is either unset or contains subprocess. And authorization is configured, meaning a real authorizer and claim mapper are in place; a deployment running with no authorizer already grants every caller unrestricted access to every namespace, so it has no namespace boundary for this to cross. Note that the separate per-namespace dynamic configuration setting workercontroller.enabled does not gate the affected path. It defaults to false, and a deployment that has never set it in any namespace is still affected, which was confirmed by running an affected release with no value for that setting present anywhere in dynamic configuration. To look for a compute configuration that is already attached, call DescribeWorkerDeploymentVersion for each worker deployment version in each namespace and check whether any scaling group\u0027s compute provider type is subprocess."
}
],
"impacts": [
{
"descriptions": [
{
"lang": "en",
"value": "Command execution on the host running the Temporal Worker Service, as the operating system account the server process runs under, reachable from an ordinary namespace write role. That process holds the persistence credentials for every namespace in the cluster as well as the cluster\u0027s TLS material, so the effect is cross-namespace and cluster-wide rather than confined to the caller\u0027s own namespace. In the official container image the server runs as an unprivileged account rather than root, which bounds host takeover but does not bound access to the credentials and key material the server process itself holds."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1188",
"description": "CWE-1188: Initialization of a Resource with an Insecure Default",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T11:41:23.342Z",
"orgId": "61241ed8-fa44-4f23-92db-b8c443751968",
"shortName": "Temporal"
},
"references": [
{
"name": "First fixed release",
"tags": [
"release-notes"
],
"url": "https://github.com/temporalio/temporal/releases/tag/v1.32.0"
},
{
"name": "Temporal Server 1.31.3, first fixed 1.31 release",
"tags": [
"release-notes"
],
"url": "https://github.com/temporalio/temporal/releases/tag/v1.31.3"
},
{
"name": "Fix pull request, compute provider allowlist changed to deny by default",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/temporal-auto-scaled-workers/pull/129"
},
{
"name": "Module bump carrying the fix into the Temporal Server 1.32 release branch",
"tags": [
"patch"
],
"url": "https://github.com/temporalio/temporal/pull/12021"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUpgrade to Temporal Server 1.32.0 or 1.31.3. Both pin a Worker Controller Instance module revision whose compute provider allowlist denies by default instead of permitting every registered provider. Operators who cannot upgrade immediately can apply the workaround below, which closes the same path without waiting for a release. The 1.30 release line does not depend on the Worker Controller Instance module at all and is unaffected. Note that the change shipped in 1.32.0 and 1.31.3 makes the allowlist deny by default and does not change where the executed command comes from: for a compute provider an operator does deliberately add to the allowlist, the program name and argument vector still arrive in the caller\u0027s request.\u003c/p\u003e"
}
],
"value": "Upgrade to Temporal Server 1.32.0 or 1.31.3. Both pin a Worker Controller Instance module revision whose compute provider allowlist denies by default instead of permitting every registered provider. Operators who cannot upgrade immediately can apply the workaround below, which closes the same path without waiting for a release. The 1.30 release line does not depend on the Worker Controller Instance module at all and is unaffected. Note that the change shipped in 1.32.0 and 1.31.3 makes the allowlist deny by default and does not change where the executed command comes from: for a compute provider an operator does deliberately add to the allowlist, the program name and argument vector still arrive in the caller\u0027s request."
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eSet the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled to an explicit list naming only the compute providers the deployment intends to permit, omitting subprocess. An explicit empty list denies every compute provider. Leaving the setting unset is what permits everything, because the allowlist check is skipped when no value is configured; giving the setting any explicit value, an empty list included, makes the check run and denies any provider absent from the list. The request is then rejected with InvalidArgument before the provider runs. This is dynamic configuration, so it takes effect without restarting the server and is available during an incident rather than only at a maintenance window. Verify the effective value for every namespace in scope, including any namespace-constrained entries that could override a cluster-wide value.\u003c/p\u003e"
}
],
"value": "Set the per-namespace dynamic configuration setting workercontroller.compute_providers.enabled to an explicit list naming only the compute providers the deployment intends to permit, omitting subprocess. An explicit empty list denies every compute provider. Leaving the setting unset is what permits everything, because the allowlist check is skipped when no value is configured; giving the setting any explicit value, an empty list included, makes the check run and denies any provider absent from the list. The request is then rejected with InvalidArgument before the provider runs. This is dynamic configuration, so it takes effect without restarting the server and is available during an incident rather than only at a maintenance window. Verify the effective value for every namespace in scope, including any namespace-constrained entries that could override a cluster-wide value."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "61241ed8-fa44-4f23-92db-b8c443751968",
"assignerShortName": "Temporal",
"cveId": "CVE-2026-89139",
"datePublished": "2026-09-21T11:41:23.342Z",
"dateReserved": "2026-09-10T23:08:25.314Z",
"dateUpdated": "2026-09-21T15:24:46.549Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86711 (GCVE-0-2026-86711)
Vulnerability from cvelistv5 – Published: 2026-09-08 11:23 – Updated: 2026-09-08 12:17- CWE-749 - Exposed Dangerous Method or Function
| URL | Tags |
|---|---|
| https://github.com/electerm/electerm/security/adv… | vendor-advisory |
| https://github.com/electerm/electerm/issues/4509 | issue-tracking |
| https://github.com/electerm/electerm/commit/b1f88… | patch |
| https://github.com/electerm/electerm/releases/tag… | release-notes |
| https://github.com/electerm/electerm/blob/v5.3.5/… | technical-description |
| https://github.com/electerm/electerm | product |
| https://www.vulncheck.com/advisories/electerm-bef… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86711",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T12:17:21.327129Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T12:17:37.026Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://github.com/electerm/electerm",
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/electerm",
"product": "electerm",
"repo": "https://github.com/electerm/electerm",
"vendor": "electerm",
"versions": [
{
"lessThan": "5.3.15",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:electerm_project:electerm:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.3.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Siyang Wu"
}
],
"datePublic": "2026-08-25T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke openFileWithEditor and other functions with arbitrary arguments to execute system commands in the main process."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T11:23:04.485Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-qc8j-6jr2-qr32)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/electerm/electerm/security/advisories/GHSA-qc8j-6jr2-qr32"
},
{
"name": "Reporter Disclosure Issue",
"tags": [
"issue-tracking"
],
"url": "https://github.com/electerm/electerm/issues/4509"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/electerm/electerm/commit/b1f880534b8ae066c5d25bbf291ca7437e052750"
},
{
"name": "electerm v5.3.15 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/electerm/electerm/releases/tag/v5.3.15"
},
{
"name": "ipcMain.handle(\u0027async\u0027) dispatches asyncGlobals[name] with no allowlist, v5.3.5",
"tags": [
"technical-description"
],
"url": "https://github.com/electerm/electerm/blob/v5.3.5/src/app/lib/ipc.js"
},
{
"tags": [
"product"
],
"url": "https://github.com/electerm/electerm"
},
{
"name": "VulnCheck Advisory: electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/electerm-before-5.3.15-arbitrary-command-execution-via-unvalidated-runglobalasync-ipc-bridge"
}
],
"title": "electerm before 5.3.15 Arbitrary Command Execution via Unvalidated runGlobalAsync IPC Bridge",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-86711",
"datePublished": "2026-09-08T11:23:04.485Z",
"dateReserved": "2026-09-08T10:58:20.106Z",
"dateUpdated": "2026-09-08T12:17:37.026Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86157 (GCVE-0-2026-86157)
Vulnerability from cvelistv5 – Published: 2026-09-29 06:34 – Updated: 2026-09-30 15:28- CWE-749 - Exposed Dangerous Method or Function
| URL | Tags |
|---|---|
| https://www.telerik.com/fiddler/fiddler-everywher… | vendor-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Everywhere |
Affected:
1.0.0 , < 8.2.0
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86157",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:18:29.456254Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:20.346Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Progress\u00ae Telerik\u00ae Fiddler\u00ae Everywhere",
"vendor": "Progress Software",
"versions": [
{
"lessThan": "8.2.0",
"status": "affected",
"version": "1.0.0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ezinne Kalu (github.com/zikk090)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files."
}
],
"value": "Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled content. Successful exploitation could result in disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of application-generated configuration files."
}
],
"impacts": [
{
"capecId": "CAPEC-122",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-122 Privilege Abuse."
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749 Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:06:18.125Z",
"orgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
"shortName": "ProgressSoftware"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.telerik.com/fiddler/fiddler-everywhere/documentation/knowledge-base/kb-security-exposed-dangerous-method-or-function-cve-2026-86157"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Users should verify that Fiddler Everywhere shortcuts have not been modified with additional command-line arguments, verify the configured browser executable path, and avoid using application-generated authentication links when manual authentication is available."
}
],
"value": "Users should verify that Fiddler Everywhere shortcuts have not been modified with additional command-line arguments, verify the configured browser executable path, and avoid using application-generated authentication links when manual authentication is available."
}
],
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
"assignerShortName": "ProgressSoftware",
"cveId": "CVE-2026-86157",
"datePublished": "2026-09-29T06:34:17.555Z",
"dateReserved": "2026-09-05T09:09:32.191Z",
"dateUpdated": "2026-09-30T15:28:20.346Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77521 (GCVE-0-2026-77521)
Vulnerability from cvelistv5 – Published: 2026-09-21 20:45 – Updated: 2026-09-22 13:32| URL | Tags |
|---|---|
| https://github.com/1Panel-dev/MaxKB/security/advi… | x_refsource_CONFIRM |
| https://github.com/1Panel-dev/MaxKB/commit/594f50… | x_refsource_MISC |
| https://github.com/1Panel-dev/MaxKB/releases/tag/… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| 1Panel-dev | MaxKB |
Affected:
< 2.10.5-lts
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77521",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T13:31:58.194506Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T13:32:19.198Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "MaxKB",
"vendor": "1Panel-dev",
"versions": [
{
"status": "affected",
"version": "\u003c 2.10.5-lts"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container\u0027s string-based gosu wrapper allowed shell metacharacters to execute outside the intended sandbox. This issue is fixed in version 2.10.5-lts."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-78",
"description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-250",
"description": "CWE-250: Execution with Unnecessary Privileges",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T20:45:14.750Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
},
{
"name": "https://github.com/1Panel-dev/MaxKB/commit/594f50f2ea80a502d1c955371ba0438b277c30ea",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/1Panel-dev/MaxKB/commit/594f50f2ea80a502d1c955371ba0438b277c30ea"
},
{
"name": "https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.5-lts",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.5-lts"
}
],
"source": {
"advisory": "GHSA-f36j-f34j-h3rx",
"discovery": "UNKNOWN"
},
"title": "MaxKB: Prompt-injectable agent can lead to command execution"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77521",
"datePublished": "2026-09-21T20:45:14.750Z",
"dateReserved": "2026-08-20T20:23:02.507Z",
"dateUpdated": "2026-09-22T13:32:19.198Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75810 (GCVE-0-2026-75810)
Vulnerability from cvelistv5 – Published: 2026-09-08 02:00 – Updated: 2026-09-17 08:48- CWE-749 - Exposed Dangerous Method or Function
| Vendor | Product | Version | |
|---|---|---|---|
| ASUS | Armoury Crate |
Affected:
through 6.5.7
(custom)
cpe:2.3:a:asus:armoury_crate:through_6.5.7:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75810",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T12:41:48.581635Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T12:41:56.403Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Armoury Crate",
"vendor": "ASUS",
"versions": [
{
"status": "affected",
"version": "through 6.5.7",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:asus:armoury_crate:through_6.5.7:*:*:*:*:*:*:*",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Exposed Dangerous Method or Function in ASUS\u0026nbsp;Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.\u003cdiv\u003eRefer to the \u0027\nSecurity Update for Armoury Crate App\u0026nbsp;\u0027 section on the ASUS Security Advisory for more information.\u003c/div\u003e"
}
],
"value": "Exposed Dangerous Method or Function in ASUS\u00a0Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the \u0027\nSecurity Update for Armoury Crate App\u00a0\u0027 section on the ASUS Security Advisory for more information."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T08:48:07.957Z",
"orgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
"shortName": "ASUS"
},
"references": [
{
"url": "https://www.asus.com/security-advisory"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "54bf65a7-a193-42d2-b1ba-8e150d3c35e1",
"assignerShortName": "ASUS",
"cveId": "CVE-2026-75810",
"datePublished": "2026-09-08T02:00:45.043Z",
"dateReserved": "2026-08-18T09:44:04.634Z",
"dateUpdated": "2026-09-17T08:48:07.957Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68928 (GCVE-0-2026-68928)
Vulnerability from cvelistv5 – Published: 2026-09-18 20:40 – Updated: 2026-09-21 18:27| URL | Tags |
|---|---|
| https://github.com/Acode-Foundation/Acode/securit… | x_refsource_CONFIRM |
| https://github.com/Acode-Foundation/Acode/pull/2442 | x_refsource_MISC |
| https://github.com/Acode-Foundation/Acode/commit/… | x_refsource_MISC |
| https://github.com/Acode-Foundation/Acode/release… | x_refsource_MISC |
| Vendor | Product | Version | |
|---|---|---|---|
| Acode-Foundation | Acode |
Affected:
>= 1.11.6, < 1.12.7
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68928",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T18:26:56.036039Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:27:19.972Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/Acode-Foundation/Acode/security/advisories/GHSA-wm94-wp33-43gx"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Acode",
"vendor": "Acode-Foundation",
"versions": [
{
"status": "affected",
"version": "\u003e= 1.11.6, \u003c 1.12.7"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an attacker-controlled cmd value, which the terminal implementation passes to ProcessBuilder with sh -c inside Acode\u0027s UID. This allows a zero-permission local application to execute commands with access to Acode private data, remote credentials, Storage Access Framework grants, and runtime permissions without additional interaction at attack time. This issue is fixed in version 1.12.7."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-926",
"description": "CWE-926: Improper Export of Android Application Components",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T20:40:12.495Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/Acode-Foundation/Acode/security/advisories/GHSA-wm94-wp33-43gx",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/Acode-Foundation/Acode/security/advisories/GHSA-wm94-wp33-43gx"
},
{
"name": "https://github.com/Acode-Foundation/Acode/pull/2442",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Acode-Foundation/Acode/pull/2442"
},
{
"name": "https://github.com/Acode-Foundation/Acode/commit/0a5237a3b140562dac877868137a784d6531894d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Acode-Foundation/Acode/commit/0a5237a3b140562dac877868137a784d6531894d"
},
{
"name": "https://github.com/Acode-Foundation/Acode/releases/tag/v1.12.7",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/Acode-Foundation/Acode/releases/tag/v1.12.7"
}
],
"source": {
"advisory": "GHSA-wm94-wp33-43gx",
"discovery": "UNKNOWN"
},
"title": "Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-68928",
"datePublished": "2026-09-18T20:40:12.495Z",
"dateReserved": "2026-07-31T21:49:24.927Z",
"dateUpdated": "2026-09-21T18:27:19.972Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-68823 (GCVE-0-2026-68823)
Vulnerability from cvelistv5 – Published: 2026-08-06 22:37 – Updated: 2026-09-29 20:23 Exclusively Hosted Service- CWE-749 - Exposed Dangerous Method or Function
| URL | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerabi… | vendor-advisorypatch |
| Vendor | Product | Version | |
|---|---|---|---|
| Microsoft | Azure Confidential Ledger |
Affected:
-
cpe:2.3:a:microsoft:azure_confidential_ledger:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-68823",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-07T17:29:35.083081Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-07T17:30:06.118Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Azure Confidential Ledger",
"vendor": "Microsoft",
"versions": [
{
"status": "affected",
"version": "-"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:azure_confidential_ledger:*:*:*:*:*:*:*:*",
"versionStartIncluding": "-",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-08-06T14:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T20:23:02.161Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Azure Confidential Ledger Remote Code Execution Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68823"
}
],
"tags": [
"exclusively-hosted-service"
],
"title": "Azure Confidential Ledger Remote Code Execution Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-68823",
"datePublished": "2026-08-06T22:37:41.958Z",
"dateReserved": "2026-07-31T16:41:44.244Z",
"dateUpdated": "2026-09-29T20:23:02.161Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
If you must expose a method, make sure to perform input validation on all arguments, limit access to authorized parties, and protect against all possible vulnerabilities.
Mitigation
Strategy: Attack Surface Reduction
- Identify all exposed functionality. Explicitly list all functionality that must be exposed to some user or set of users. Identify which functionality may be:
- Ensure that the implemented code follows these expectations. This includes setting the appropriate access modifiers where applicable (public, private, protected, etc.) or not marking ActiveX controls safe-for-scripting.
- accessible to all users
- restricted to a small set of privileged users
- prevented from being directly accessible at all
CAPEC-500: WebView Injection
An adversary, through a previously installed malicious application, injects code into the context of a web page displayed by a WebView component. Through the injected code, an adversary is able to manipulate the DOM tree and cookies of the page, expose sensitive information, and can launch attacks against the web application from within the web page.