CWE-915
AllowedImproperly Controlled Modification of Dynamically-Determined Object Attributes
Abstraction: Base · Status: Incomplete
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
336 vulnerabilities reference this CWE, most recent first.
CVE-2026-103235 (GCVE-0-2026-103235)
Vulnerability from cvelistv5 – Published: 2026-09-30 09:09 – Updated: 2026-09-30 14:32| URL | Tags |
|---|---|
| https://github.com/MISP/MISP/commit/d1f5684f9 | patch |
qwen3.8:27b
advisory
bcp-05-x-01bcp-05-x-02
Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.
| Model | Source | Identifier |
|---|---|---|
| qwen3.8:27b | ollama | qwen3.8:27b |
- Generator
-
patch2vuln.pyon 2026-09-30 07:37 - Model
qwen3.8:27b- Input
-
https://github.com/MISP/MISP/commit/d1f5684f9.patch
f478751165e6… - Confidence
- high
| Commit | Subject | Patch SHA-256 |
|---|---|---|
d1f5684f9a19
|
fix: [security] Delegation requests stay bound to the event | f478751165e6… |
Fix summary
The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.
Patch summary
In EventDelegationsController::delegateEvent(), the code previously saved $this->request->data['EventDelegation'] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.
CVSS rationale
Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.
Weakness rationale
- CWE-915 The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation.
- CWE-639 The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary.
Attack pattern rationale
- CAPEC-12 The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence.
Assumptions to verify
- The affected version boundary (< 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.
- PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.
- VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.
- The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.
- The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption.
Model comparison
Selected qwen3.8:27b
by deterministic-consensus-v1
The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required.
| Model | Score | Agreement | Confidence | Assumptions |
|---|---|---|---|---|
qwen3.8:27b |
6 | 9 | high | 5 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103235",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:32:35.584208Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:32:45.581Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"EventDelegationsController"
],
"product": "MISP",
"programFiles": [
"app/Controller/EventDelegationsController.php"
],
"repo": "https://github.com/MISP/MISP",
"vendor": "MISP",
"versions": [
{
"lessThan": "2.5.48",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eMISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\u003c/p\u003e\u003cp\u003eAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\u003c/p\u003e\u003cp\u003ePreconditions:\u003c/p\u003e\u003cp\u003e- An authenticated user with the delegation permission (perm_delegate)\u003c/p\u003e\u003cp\u003e- The MISP.delegation server setting must be enabled\u003c/p\u003e\u003cp\u003eImpact:\u003c/p\u003e\u003cp\u003e- Confidentiality: read access to any event on the instance\u003c/p\u003e\u003cp\u003e- Integrity: overwriting existing delegation records and transferring event ownership\u003c/p\u003e\u003cp\u003eAffected versions: MISP \u0026lt; 2.5.48\u003c/p\u003e"
}
],
"value": "MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP \u003c 2.5.48"
}
],
"impacts": [
{
"capecId": "CAPEC-12",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-12 Mass Assignment"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T09:12:56.533Z",
"orgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"shortName": "CIRCL"
},
"references": [
{
"name": "Security patch",
"tags": [
"patch"
],
"url": "https://github.com/MISP/MISP/commit/d1f5684f9"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.\u003c/p\u003e"
}
],
"value": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events",
"x_gcve": [
{
"extensions": {
"bcp-05-x-01": {
"ai_annotations": [
{
"ai_level": "generated",
"description": "Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.",
"gna_source": 1,
"models": [
{
"gna_source": 1,
"identifier": "qwen3.8:27b",
"name": "qwen3.8:27b",
"source": "ollama"
}
],
"review_status": "full",
"scope": "record",
"tags": [
"ai-computer-assisted:llm-generated",
"ai-computer-assisted:classification"
]
}
]
},
"bcp-05-x-02": {
"x_patch2vuln": {
"assumptions": [
"The affected version boundary (\u003c 2.5.48) is inferred from the tag_version_boundary metadata showing v2.5.48 as the nearest tag with 22 commits after the fix; the exact last affected release is not explicitly stated in the patch.",
"PR:L assumes the attacker needs only the perm_delegate permission, which is a non-admin role; the exact role configuration may vary by deployment.",
"VA:N assumes the availability impact (deletion of the original event) requires victim acceptance and is therefore not a direct availability impact of the vulnerability itself.",
"The CAPEC-12 mapping is the closest standard pattern; the vulnerability also has IDOR characteristics (CWE-639) but CAPEC-12 best captures the mass-assignment mechanism demonstrated in the patch.",
"The MISP.delegation server setting must be enabled for the vulnerability to be exploitable; this is a deployment configuration assumption."
],
"capecRationale": [
{
"capecId": "CAPEC-12",
"rationale": "The attacker manipulates hidden or additional fields in a form/API request (injecting id and event_id into the EventDelegation payload) to modify data beyond what the application intended to accept. This is the canonical mass assignment pattern: the server processes user-supplied fields it should have ignored. The mapping is direct and well-supported by the patch evidence."
}
],
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"confidence": "high",
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Jeroen Pinoy"
},
{
"lang": "en",
"type": "remediation developer",
"value": "iglocska"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Claude Opus 5"
}
],
"cvssRationale": "Network vector: MISP is a web application accessible over HTTP. Low complexity: a single crafted POST request suffices. No attack target manipulation. Low privileges: requires an authenticated user with perm_delegate. No user interaction: read access is granted immediately upon creating the retargeted delegation. High confidentiality: grants read access to any event on the instance. High integrity: overwrites existing delegation records and can transfer event ownership. No availability impact without victim acceptance. Scope change (SC:H, SI:H): the vulnerability crosses organisational boundaries, affecting data owned by other organisations. No sub-system availability impact.",
"fixSummary": "The delegation record is now constructed from a strict allow-list of fields rather than persisting the raw user-submitted payload. The event_id is always derived from the authorized event in the URL, the requester_org_id is always taken from the authenticated session, and the primary key is never included in the saved data. Only message, distribution, and sharing_group_id are accepted from user input, eliminating the ability to retarget or overwrite existing delegation records.",
"generatedAt": "2026-09-30T07:37:05.841152Z",
"generator": "patch2vuln.py",
"model": "qwen3.8:27b",
"modelComparison": {
"rankings": [
{
"agreementScore": 9,
"assumptionCount": 5,
"confidence": "high",
"model": "qwen3.8:27b",
"score": 6
}
],
"selectedModel": "qwen3.8:27b",
"selectionMethod": "deterministic-consensus-v1",
"selectionNotice": "The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."
},
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"patchSummary": "In EventDelegationsController::delegateEvent(), the code previously saved $this-\u003erequest-\u003edata[\u0027EventDelegation\u0027] directly after setting a few fields. The fix replaces this with an explicit allow-list array containing only event_id (from the authorized URL event), requester_org_id (from the session), org_id (resolved from submitted UUID), message, distribution, and sharing_group_id. The primary key id is never included. A regression test class DelegationRequestRetargeting was added to verify that injecting a nested EventDelegation with a foreign id and event_id does not grant read access to the victim event.",
"patchTruncated": false,
"patches": [
{
"commit": "d1f5684f9a193ea0a8a4f7709703011aa69d9682",
"patchSha256": "f478751165e658f2b26822845ec034386d8a1740527cf30863792e9521f24611",
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"sourceUrl": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event"
}
],
"source": "https://github.com/MISP/MISP/commit/d1f5684f9.patch",
"subject": "fix: [security] Delegation requests stay bound to the event",
"tagVersionBoundary": {
"commits_after_fix": 22,
"repository": "https://github.com/MISP/MISP",
"tag": "v2.5.48",
"version": "2.5.48",
"version_type": "semver"
},
"weaknessRationale": [
{
"cweId": "CWE-915",
"rationale": "The application persisted the entire user-submitted record including fields (id, event_id) that should not be attacker-controllable, allowing mass assignment of sensitive fields to retarget the delegation."
},
{
"cweId": "CWE-639",
"rationale": "The authorization check validated only the event in the URL, but the attacker-supplied primary key or event_id in the payload redirected the operation to a different record, bypassing the intended authorization boundary."
}
]
}
}
},
"recordType": "advisory",
"vulnId": "GCVE-1-2026-20227"
}
],
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "5a6e4751-2f3f-4070-9419-94fb35b644e8",
"assignerShortName": "CIRCL",
"cveId": "CVE-2026-103235",
"datePublished": "2026-09-30T09:09:36.761Z",
"dateReserved": "2026-09-30T09:09:33.466Z",
"dateUpdated": "2026-09-30T14:32:45.581Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93752 (GCVE-0-2026-93752)
Vulnerability from cvelistv5 – Published: 2026-09-18 17:51 – Updated: 2026-09-24 14:23- CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
| URL | Tags |
|---|---|
| https://github.com/NV/CSSOM/issues/119 | issue-tracking |
| https://github.com/NV/CSSOM | product |
| https://github.com/NV/CSSOM/blob/00ec21868e124225… | technical-description |
| https://github.com/NV/CSSOM/blob/00ec21868e124225… | technical-description |
| https://www.vulncheck.com/advisories/cssom-throug… | third-party-advisory |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93752",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T19:48:46.423602Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T19:49:14.421Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/NV/CSSOM/issues/119"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/cssom",
"product": "CSSOM",
"vendor": "NV",
"versions": [
{
"lessThanOrEqual": "0.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Wayde Shi (PayPal Cyber Security Team)"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal counter and trigger excessive memory allocation during cssText serialization, causing process termination."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:11.127Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #119",
"tags": [
"issue-tracking"
],
"url": "https://github.com/NV/CSSOM/issues/119"
},
{
"tags": [
"product"
],
"url": "https://github.com/NV/CSSOM"
},
{
"name": "setProperty() writing a declaration name over the internal length field",
"tags": [
"technical-description"
],
"url": "https://github.com/NV/CSSOM/blob/00ec21868e12422581c81779135c2f1648441204/lib/CSSStyleDeclaration.js#L41-L56"
},
{
"name": "cssText getter using the replaced counter as an array bound",
"tags": [
"technical-description"
],
"url": "https://github.com/NV/CSSOM/blob/00ec21868e12422581c81779135c2f1648441204/lib/CSSStyleDeclaration.js#L112-L124"
},
{
"name": "VulnCheck Advisory: CSSOM through 0.5.0 Denial of Service via length Property",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/cssom-through-0.5.0-denial-of-service-via-length-property"
}
],
"title": "CSSOM through 0.5.0 Denial of Service via length Property",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93752",
"datePublished": "2026-09-18T17:51:37.079Z",
"dateReserved": "2026-09-18T16:30:18.480Z",
"dateUpdated": "2026-09-24T14:23:11.127Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93477 (GCVE-0-2026-93477)
Vulnerability from cvelistv5 – Published: 2026-09-25 07:08 – Updated: 2026-09-25 13:26- CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
| Vendor | Product | Version | |
|---|---|---|---|
| ash-project | ash |
Affected:
2.17.15 , < 3.33.11
(semver)
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:* |
|
| ash-project | ash |
Affected:
8c17434803b2e91de522bdfbd0ca918e5d5898df , < 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f
(git)
cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93477",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T13:26:14.200048Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T13:26:42.369Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.Ash.Actions.Destroy.Bulk\u0027",
"\u0027Elixir.Ash.Actions.Update.Bulk\u0027"
],
"packageName": "ash",
"packageURL": "pkg:hex/ash",
"product": "ash",
"programFiles": [
"lib/ash/actions/destroy/bulk.ex",
"lib/ash/actions/update/bulk.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.Ash.Actions.Destroy.Bulk\u0027:base_changeset/5"
},
{
"name": "\u0027Elixir.Ash.Actions.Update.Bulk\u0027:base_changeset/5"
}
],
"repo": "https://github.com/ash-project/ash",
"vendor": "ash-project",
"versions": [
{
"lessThan": "3.33.11",
"status": "affected",
"version": "2.17.15",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.Ash.Actions.Destroy.Bulk\u0027",
"\u0027Elixir.Ash.Actions.Update.Bulk\u0027"
],
"packageName": "ash-project/ash",
"packageURL": "pkg:github/ash-project/ash",
"product": "ash",
"programFiles": [
"lib/ash/actions/destroy/bulk.ex",
"lib/ash/actions/update/bulk.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.Ash.Actions.Destroy.Bulk\u0027:base_changeset/5"
},
{
"name": "\u0027Elixir.Ash.Actions.Update.Bulk\u0027:base_changeset/5"
}
],
"repo": "https://github.com/ash-project/ash",
"vendor": "ash-project",
"versions": [
{
"lessThan": "6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f",
"status": "affected",
"version": "8c17434803b2e91de522bdfbd0ca918e5d5898df",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn action must declare a private argument (\u003ccode\u003epublic?: false\u003c/code\u003e) that is referenced by an \u003ccode\u003earg(...)\u003c/code\u003e template in one of its changes or validations, be invocable as a bulk destroy or bulk update, and the application must pass untrusted user-supplied parameters into \u003ccode\u003eAsh.bulk_destroy/4\u003c/code\u003e or \u003ccode\u003eAsh.bulk_update/4\u003c/code\u003e (directly or through AshJsonApi/AshGraphql).\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "An action must declare a private argument (`public?: false`) that is referenced by an `arg(...)` template in one of its changes or validations, be invocable as a bulk destroy or bulk update, and the application must pass untrusted user-supplied parameters into `Ash.bulk_destroy/4` or `Ash.bulk_update/4` (directly or through AshJsonApi/AshGraphql)."
}
],
"value": "An action must declare a private argument (public?: false) that is referenced by an arg(...) template in one of its changes or validations, be invocable as a bulk destroy or bulk update, and the application must pass untrusted user-supplied parameters into Ash.bulk_destroy/4 or Ash.bulk_update/4 (directly or through AshJsonApi/AshGraphql)."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.33.11",
"versionStartIncluding": "2.17.15",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "zx"
},
{
"lang": "en",
"type": "reporter",
"value": "zx"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Zach Daniel / Ash Project"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"dateAssigned": "2026-09-25T06:50:10.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths.\u003c/p\u003e\n\u003cp\u003eAction arguments declared with \u003ccode\u003epublic?: false\u003c/code\u003e are meant to be set only by trusted server-side code (for example via \u003ccode\u003eAsh.Changeset.set_private_argument/3\u003c/code\u003e) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eAsh.Actions.Destroy.Bulk.base_changeset/5\u003c/code\u003e and \u003ccode\u003eAsh.Actions.Update.Bulk.base_changeset/5\u003c/code\u003e match every key in the caller-supplied parameter map against all of the action\u0027s arguments with no \u003ccode\u003epublic?\u003c/code\u003e check, then apply the matches to the base changeset. A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to \u003ccode\u003eAsh.bulk_destroy/4\u003c/code\u003e or \u003ccode\u003eAsh.bulk_update/4\u003c/code\u003e) can therefore set any private argument of that action, including one referenced by an \u003ccode\u003earg(...)\u003c/code\u003e template in the action\u0027s changes or validations. Depending on how the application uses the argument (for example an \u003ccode\u003eacting_user_id\u003c/code\u003e driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation.\u003c/p\u003e\n\u003cp\u003eThe fix requires \u003ccode\u003epublic?\u003c/code\u003e in the argument matching on both bulk paths; private arguments remain settable server-side via the \u003ccode\u003e:private_arguments\u003c/code\u003e option.\u003c/p\u003e\n\u003cp\u003eThis issue affects ash: from 2.17.15 before 3.33.11.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths.\n\nAction arguments declared with `public?: false` are meant to be set only by trusted server-side code (for example via `Ash.Changeset.set_private_argument/3`) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered.\n\n`Ash.Actions.Destroy.Bulk.base_changeset/5` and `Ash.Actions.Update.Bulk.base_changeset/5` match every key in the caller-supplied parameter map against all of the action\u0027s arguments with no `public?` check, then apply the matches to the base changeset. A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to `Ash.bulk_destroy/4` or `Ash.bulk_update/4`) can therefore set any private argument of that action, including one referenced by an `arg(...)` template in the action\u0027s changes or validations. Depending on how the application uses the argument (for example an `acting_user_id` driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation.\n\nThe fix requires `public?` in the argument matching on both bulk paths; private arguments remain settable server-side via the `:private_arguments` option.\n\nThis issue affects ash: from 2.17.15 before 3.33.11."
}
],
"value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths.\n\nAction arguments declared with public?: false are meant to be set only by trusted server-side code (for example via Ash.Changeset.set_private_argument/3) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered.\n\nAsh.Actions.Destroy.Bulk.base_changeset/5 and Ash.Actions.Update.Bulk.base_changeset/5 match every key in the caller-supplied parameter map against all of the action\u0027s arguments with no public? check, then apply the matches to the base changeset. A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to Ash.bulk_destroy/4 or Ash.bulk_update/4) can therefore set any private argument of that action, including one referenced by an arg(...) template in the action\u0027s changes or validations. Depending on how the application uses the argument (for example an acting_user_id driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation.\n\nThe fix requires public? in the argument matching on both bulk paths; private arguments remain settable server-side via the :private_arguments option.\n\nThis issue affects ash: from 2.17.15 before 3.33.11."
}
],
"impacts": [
{
"capecId": "CAPEC-77",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-77 Manipulating User-Controlled Variables"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T07:08:55.191Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"name": "GHSA-c2p4-p7q6-hr2j",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j"
},
{
"name": "EEF CNA record for CVE-2026-93477",
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-93477.html"
},
{
"name": "OSV record EEF-CVE-2026-93477",
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-93477"
},
{
"name": "Introducing commit 8c17434 in ash-project/ash",
"tags": [
"related"
],
"url": "https://github.com/ash-project/ash/commit/8c17434803b2e91de522bdfbd0ca918e5d5898df"
},
{
"name": "Fix commit 6b7ac53 in ash-project/ash",
"tags": [
"patch"
],
"url": "https://github.com/ash-project/ash/commit/6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-93477",
"datePublished": "2026-09-25T07:08:55.191Z",
"dateReserved": "2026-09-19T16:00:02.004Z",
"dateUpdated": "2026-09-25T13:26:42.369Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93364 (GCVE-0-2026-93364)
Vulnerability from cvelistv5 – Published: 2026-09-25 16:57 – Updated: 2026-10-01 15:22 X_Open Source- CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
| URL | Tags |
|---|---|
| https://gist.github.com/akinerkisa/6a7532442795be… | technical-description |
| https://www.vulncheck.com/advisories/bludit-cms-m… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Bludit | Bludit CMS |
Affected:
0 , ≤ 3.22.0
(semver)
Affected: 0 , ≤ 4.0.0-beta-1 (custom) Affected: 0 , ≤ 074773eff34b91c002ab9d99029a3edca4934bf1 (git) cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:* cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93364",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T17:42:49.466454Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T17:42:59.038Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"packageURL": "pkg:github/bludit/bludit",
"product": "Bludit CMS",
"repo": "https://github.com/bludit/bludit",
"vendor": "Bludit",
"versions": [
{
"lessThanOrEqual": "3.22.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.0.0-beta-1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "074773eff34b91c002ab9d99029a3edca4934bf1",
"status": "affected",
"version": "0",
"versionType": "git"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.22.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.0.0-beta-1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ak\u0131ner K\u0131sa (`akinerkisa`)"
}
],
"datePublic": "2026-09-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:22:00.961Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"technical-description"
],
"url": "https://gist.github.com/akinerkisa/6a7532442795beefd29b9c55a100eb16"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/bludit-cms-mass-assignment-privilege-escalation-via-pages-edit"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93364",
"datePublished": "2026-09-25T16:57:38.544Z",
"dateReserved": "2026-09-17T18:41:40.758Z",
"dateUpdated": "2026-10-01T15:22:00.961Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92217 (GCVE-0-2026-92217)
Vulnerability from cvelistv5 – Published: 2026-09-16 02:00 – Updated: 2026-09-17 17:06| URL | Tags |
|---|---|
| https://vuldb.com/vuln/404462 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/404462/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-92217 | third-party-advisory |
| https://vuldb.com/submit/934116 | third-party-advisory |
| https://github.com/a2ui-project/a2ui/issues/2297 | issue-tracking |
| https://github.com/a2ui-project/a2ui/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| a2ui-project | a2ui |
Affected:
0.10.0
Affected: 0.10.1 Affected: 0.10.2 Affected: 0.10.3 Affected: 0.10.4 Affected: 0.10.5 Affected: 0.10.6 cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92217",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-17T17:05:56.534863Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T17:06:13.556Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:*"
],
"modules": [
"Message Parsing"
],
"product": "a2ui",
"vendor": "a2ui-project",
"versions": [
{
"status": "affected",
"version": "0.10.0"
},
{
"status": "affected",
"version": "0.10.1"
},
{
"status": "affected",
"version": "0.10.2"
},
{
"status": "affected",
"version": "0.10.3"
},
{
"status": "affected",
"version": "0.10.4"
},
{
"status": "affected",
"version": "0.10.5"
},
{
"status": "affected",
"version": "0.10.6"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "colorfullbz (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determined object attributes. The attack can be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-913",
"description": "Dynamically-Managed Code Resources",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T02:00:16.889Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-404462 | a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determined object attributes",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/404462"
},
{
"name": "VDB-404462 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/404462/cti"
},
{
"name": "CVE-2026-92217 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-92217"
},
{
"name": "Submit #934116 | a2ui-project a2ui 0.10.6 CWE-20",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/934116"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/a2ui-project/a2ui/issues/2297"
},
{
"tags": [
"product"
],
"url": "https://github.com/a2ui-project/a2ui/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-15T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-15T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-15T20:34:32.000Z",
"value": "VulDB entry last update"
}
],
"title": "a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determined object attributes",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-92217",
"datePublished": "2026-09-16T02:00:16.889Z",
"dateReserved": "2026-09-15T18:29:12.619Z",
"dateUpdated": "2026-09-17T17:06:13.556Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-85408 (GCVE-0-2026-85408)
Vulnerability from cvelistv5 – Published: 2026-09-04 04:15 – Updated: 2026-09-11 20:37| URL | Tags |
|---|---|
| https://vuldb.com/vuln/398558 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/398558/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-85408 | third-party-advisory |
| https://vuldb.com/submit/894906 | third-party-advisory |
| https://drive.google.com/file/d/1fVUqrUoO29zkq2Ib… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Eleveo | Quality Management |
Affected:
9.7.0
cpe:2.3:a:eleveo:quality_management:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-85408",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T20:05:04.874348Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T20:37:42.970Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:eleveo:quality_management:*:*:*:*:*:*:*:*"
],
"modules": [
"Conversation Handler"
],
"product": "Quality Management",
"vendor": "Eleveo",
"versions": [
{
"status": "affected",
"version": "9.7.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "omarelshopky (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/\u003cID\u003e/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 4,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-913",
"description": "Dynamically-Managed Code Resources",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T04:15:09.212Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-398558 | Eleveo Quality Management Conversation events dynamically-determined object attributes",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/398558"
},
{
"name": "VDB-398558 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/398558/cti"
},
{
"name": "CVE-2026-85408 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-85408"
},
{
"name": "Submit #894906 | Eleveo Quality Management 9.7.0 Mass Assignment",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894906"
},
{
"tags": [
"exploit"
],
"url": "https://drive.google.com/file/d/1fVUqrUoO29zkq2Ib_TXFNavX9yDo-Vp6/view?usp=sharing"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-03T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-03T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-03T20:50:26.000Z",
"value": "VulDB entry last update"
}
],
"title": "Eleveo Quality Management Conversation events dynamically-determined object attributes",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-85408",
"datePublished": "2026-09-04T04:15:09.212Z",
"dateReserved": "2026-09-03T18:45:04.248Z",
"dateUpdated": "2026-09-11T20:37:42.970Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84430 (GCVE-0-2026-84430)
Vulnerability from cvelistv5 – Published: 2026-09-02 00:45 – Updated: 2026-09-02 13:01| URL | Tags |
|---|---|
| https://vuldb.com/vuln/397797 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/397797/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-84430 | third-party-advisory |
| https://vuldb.com/submit/884061 | third-party-advisory |
| https://github.com/Angoddess/CVE/blob/main/README.md | exploit |
| https://gitee.com/gouguopen/office/releases/tag/v6.0.3 | patch |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84430",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T13:01:11.993306Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T13:01:37.429Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:gouguoa:gouguoa:*:*:*:*:*:*:*:*"
],
"modules": [
"edit_personal Endpoint"
],
"product": "gouguoa",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"status": "affected",
"version": "5.1"
},
{
"status": "affected",
"version": "5.2"
},
{
"status": "affected",
"version": "5.3"
},
{
"status": "affected",
"version": "5.4"
},
{
"status": "affected",
"version": "5.5"
},
{
"status": "affected",
"version": "5.6"
},
{
"status": "affected",
"version": "5.7"
},
{
"status": "affected",
"version": "5.8"
},
{
"status": "affected",
"version": "5.9"
},
{
"status": "affected",
"version": "5.10.0"
},
{
"status": "affected",
"version": "6.0.0"
},
{
"status": "affected",
"version": "6.0.1"
},
{
"status": "unaffected",
"version": "6.0.3"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Angoddess (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upgrading the affected component is advised."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.5,
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-913",
"description": "Dynamically-Managed Code Resources",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T00:45:13.550Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-397797 | gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/397797"
},
{
"name": "VDB-397797 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/397797/cti"
},
{
"name": "CVE-2026-84430 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-84430"
},
{
"name": "Submit #884061 | gouguoa 5.x Improper Privilege Management",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/884061"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/Angoddess/CVE/blob/main/README.md"
},
{
"tags": [
"patch"
],
"url": "https://gitee.com/gouguopen/office/releases/tag/v6.0.3"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-01T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-01T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-01T20:46:59.000Z",
"value": "VulDB entry last update"
}
],
"title": "gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-84430",
"datePublished": "2026-09-02T00:45:13.550Z",
"dateReserved": "2026-09-01T18:41:46.981Z",
"dateUpdated": "2026-09-02T13:01:37.429Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-83557 (GCVE-0-2026-83557)
Vulnerability from cvelistv5 – Published: 2026-09-01 14:57 – Updated: 2026-09-01 17:46| URL | Tags |
|---|---|
| https://github.com/FasterXML/jackson-databind/sec… | third-party-advisory |
| https://github.com/FasterXML/jackson-databind/pull/6155 | patchissue-tracking |
| https://github.com/FasterXML/jackson-databind/iss… | issue-tracking |
| https://github.com/FasterXML/jackson-databind/com… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| FasterXML | jackson-databind |
Affected:
2.11.0 , < 2.18.10
(maven)
Affected: 2.19.0 , < 2.21.6 (maven) Affected: 2.22.0 , < 2.22.2 (maven) |
|
| FasterXML | jackson-databind |
Affected:
3.0.0 , < 3.1.6
(maven)
Affected: 3.2.0 , < 3.2.2 (maven) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-83557",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-01T17:46:23.527612Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T17:46:40.145Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "com.fasterxml.jackson.core:jackson-databind",
"product": "jackson-databind",
"programFiles": [
"src/main/java/com/fasterxml/jackson/databind/jsontype/DefaultBaseTypeLimitingValidator.java"
],
"programRoutines": [
{
"name": "com.fasterxml.jackson.databind.jsontype.DefaultBaseTypeLimitingValidator.isUnsafeBaseType"
}
],
"repo": "https://github.com/FasterXML/jackson-databind",
"vendor": "FasterXML",
"versions": [
{
"lessThan": "2.18.10",
"status": "affected",
"version": "2.11.0",
"versionType": "maven"
},
{
"lessThan": "2.21.6",
"status": "affected",
"version": "2.19.0",
"versionType": "maven"
},
{
"lessThan": "2.22.2",
"status": "affected",
"version": "2.22.0",
"versionType": "maven"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "tools.jackson.core:jackson-databind",
"product": "jackson-databind",
"programFiles": [
"src/main/java/tools/jackson/databind/jsontype/DefaultBaseTypeLimitingValidator.java"
],
"programRoutines": [
{
"name": "tools.jackson.databind.jsontype.DefaultBaseTypeLimitingValidator.isUnsafeBaseType"
}
],
"repo": "https://github.com/FasterXML/jackson-databind",
"vendor": "FasterXML",
"versions": [
{
"lessThan": "3.1.6",
"status": "affected",
"version": "3.0.0",
"versionType": "maven"
},
{
"lessThan": "3.2.2",
"status": "affected",
"version": "3.2.0",
"versionType": "maven"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "prvazsahnazarov"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Tatu Saloranta (cowtowncoder)"
}
],
"datePublic": "2026-09-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.\u003c/p\u003e"
}
],
"value": "DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-01T14:57:01.340Z",
"orgId": "36c7be3b-2937-45df-85ea-ca7133ea542c",
"shortName": "HeroDevs"
},
"references": [
{
"name": "GHSA-gx83-3vf8-gh7j",
"tags": [
"third-party-advisory"
],
"url": "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"
},
{
"name": "FasterXML/jackson-databind#6155",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/FasterXML/jackson-databind/pull/6155"
},
{
"name": "FasterXML/jackson-databind#6156",
"tags": [
"issue-tracking"
],
"url": "https://github.com/FasterXML/jackson-databind/issues/6156"
},
{
"name": "Fix commit (2.x line, forward-merged to 2.21, 2.22 and the 3.x branches)",
"tags": [
"patch"
],
"url": "https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUpgrade to jackson-databind 2.18.10, 2.21.6, 2.22.2 (com.fasterxml.jackson.core) or 3.1.6, 3.2.2 (tools.jackson.core). The fix adds java.lang.Comparable to the UnsafeBaseTypes denylist in DefaultBaseTypeLimitingValidator, so polymorphic resolution against a Comparable base type is denied outright. Applications that legitimately need polymorphic handling of a Comparable-typed property must configure an explicit PolymorphicTypeValidator, for example a BasicPolymorphicTypeValidator with an allow-list of permitted subtypes.\u003c/p\u003e"
}
],
"value": "Upgrade to jackson-databind 2.18.10, 2.21.6, 2.22.2 (com.fasterxml.jackson.core) or 3.1.6, 3.2.2 (tools.jackson.core). The fix adds java.lang.Comparable to the UnsafeBaseTypes denylist in DefaultBaseTypeLimitingValidator, so polymorphic resolution against a Comparable base type is denied outright. Applications that legitimately need polymorphic handling of a Comparable-typed property must configure an explicit PolymorphicTypeValidator, for example a BasicPolymorphicTypeValidator with an allow-list of permitted subtypes."
}
],
"source": {
"discovery": "EXTERNAL"
},
"timeline": [
{
"lang": "en",
"time": "2026-08-11T02:58:00.000Z",
"value": "Fix committed upstream (FasterXML/jackson-databind#6155)"
},
{
"lang": "en",
"time": "2026-09-01T00:00:00.000Z",
"value": "GitHub Security Advisory GHSA-gx83-3vf8-gh7j published by the maintainer"
}
],
"title": "jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator\u0027s unsafe base types",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eConfigure an explicit restrictive PolymorphicTypeValidator rather than relying on the default validator, or avoid declaring java.lang.Comparable as the base type of an @JsonTypeInfo-annotated property or class. Narrowing the declared base type to an application-specific interface also removes the exposure.\u003c/p\u003e"
}
],
"value": "Configure an explicit restrictive PolymorphicTypeValidator rather than relying on the default validator, or avoid declaring java.lang.Comparable as the base type of an @JsonTypeInfo-annotated property or class. Narrowing the declared base type to an application-specific interface also removes the exposure."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "36c7be3b-2937-45df-85ea-ca7133ea542c",
"assignerShortName": "HeroDevs",
"cveId": "CVE-2026-83557",
"datePublished": "2026-09-01T14:57:01.340Z",
"dateReserved": "2026-08-31T18:32:14.405Z",
"dateUpdated": "2026-09-01T17:46:40.145Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78416 (GCVE-0-2026-78416)
Vulnerability from cvelistv5 – Published: 2026-08-24 15:36 – Updated: 2026-08-26 20:59- CWE-915 - Improperly controlled modification of Dynamically-Determined object attributes
| URL | Tags |
|---|---|
| https://www.hckrt.com/hacktivity/HCKRT-JD662P | third-party-advisorytechnical-descriptionmitigation |
| https://github.com/craftcms/cms/releases/tag/5.10.6 | release-notes |
| https://github.com/craftcms/cms | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78416",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T03:56:39.218Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://packagist.org",
"defaultStatus": "unaffected",
"packageName": "craftcms/cms",
"product": "cms",
"vendor": "craftcms",
"versions": [
{
"lessThan": "4.18.2",
"status": "affected",
"version": "4.0.0-RC1",
"versionType": "semver"
},
{
"lessThan": "5.10.6",
"status": "affected",
"version": "5.0.0-RC1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.18.2",
"versionStartIncluding": "4.0.0-rc1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.6",
"versionStartIncluding": "5.0.0-rc1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "OR"
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "saladin"
},
{
"lang": "en",
"type": "coordinator",
"value": "Hackrate"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.\u003cbr\u003e"
}
],
"value": "Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user."
}
],
"impacts": [
{
"capecId": "CAPEC-242",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-242 Code Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly controlled modification of Dynamically-Determined object attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T20:59:03.683Z",
"orgId": "7004884b-51e2-48e8-b4a2-5ca29e80453e",
"shortName": "Hackrate"
},
"references": [
{
"tags": [
"third-party-advisory",
"technical-description",
"mitigation"
],
"url": "https://www.hckrt.com/hacktivity/HCKRT-JD662P"
},
{
"tags": [
"release-notes"
],
"url": "https://github.com/craftcms/cms/releases/tag/5.10.6"
},
{
"tags": [
"product"
],
"url": "https://github.com/craftcms/cms"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Authenticated RCE via `condition.config` JSON cleanse bypass",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "7004884b-51e2-48e8-b4a2-5ca29e80453e",
"assignerShortName": "Hackrate",
"cveId": "CVE-2026-78416",
"datePublished": "2026-08-24T15:36:07.971Z",
"dateReserved": "2026-08-24T15:07:04.075Z",
"dateUpdated": "2026-08-26T20:59:03.683Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-78038 (GCVE-0-2026-78038)
Vulnerability from cvelistv5 – Published: 2026-08-30 11:50 – Updated: 2026-08-31 14:55- CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
| URL | Tags |
|---|---|
| https://github.com/ash-project/ash_oban/security/… | vendor-advisoryrelated |
| https://cna.erlef.org/cves/CVE-2026-78038.html | related |
| https://osv.dev/vulnerability/EEF-CVE-2026-78038 | related |
| https://github.com/ash-project/ash_oban/commit/da… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| ash-project | ash_oban |
Affected:
0.2.5 , < 0.8.14
(semver)
cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:* |
|
| ash-project | ash_oban |
Affected:
ce079229ecdf0d323da2b554f30fc569e54660f0 , < da2d81e1e8e1dcc3e6ec8587cdb4f273575ffca3
(git)
cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-78038",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T14:54:52.126294Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T14:55:17.264Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/ash-project/ash_oban/security/advisories/GHSA-gj9p-x393-rf9h"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.AshOban\u0027"
],
"packageName": "ash_oban",
"packageURL": "pkg:hex/ash_oban",
"product": "ash_oban",
"programFiles": [
"lib/ash_oban.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.AshOban\u0027:build_trigger/3"
}
],
"repo": "https://github.com/ash-project/ash_oban",
"vendor": "ash-project",
"versions": [
{
"lessThan": "0.8.14",
"status": "affected",
"version": "0.2.5",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.AshOban\u0027"
],
"packageName": "ash-project/ash_oban",
"packageURL": "pkg:github/ash-project/ash_oban",
"product": "ash_oban",
"programFiles": [
"lib/ash_oban.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.AshOban\u0027:build_trigger/3"
}
],
"repo": "https://github.com/ash-project/ash_oban",
"vendor": "ash-project",
"versions": [
{
"lessThan": "da2d81e1e8e1dcc3e6ec8587cdb4f273575ffca3",
"status": "affected",
"version": "ce079229ecdf0d323da2b554f30fc569e54660f0",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn application must pass untrusted input into the \u003ccode\u003e:args\u003c/code\u003e option of \u003ccode\u003eAshOban.build_trigger/3\u003c/code\u003e (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected \u003ccode\u003eprimary_key\u003c/code\u003e, \u003ccode\u003etenant\u003c/code\u003e, or \u003ccode\u003eaction_arguments\u003c/code\u003e retargets the enqueued job.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "An application must pass untrusted input into the `:args` option of `AshOban.build_trigger/3` (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected `primary_key`, `tenant`, or `action_arguments` retargets the enqueued job."
}
],
"value": "An application must pass untrusted input into the :args option of AshOban.build_trigger/3 (or an equivalent scheduling helper), on a trigger whose action is an update or destroy, so that an injected primary_key, tenant, or action_arguments retargets the enqueued job."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ash-project:ash_oban:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.8.14",
"versionStartIncluding": "0.2.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Peter Ullrich"
},
{
"lang": "en",
"type": "reporter",
"value": "Peter Ullrich"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Zach Daniel / Ash Project"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eImproperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the \u003ccode\u003e:args\u003c/code\u003e option of \u003ccode\u003eAshOban.build_trigger/3\u003c/code\u003e to retarget an update or destroy trigger at another record, including across tenants.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003ebuild_trigger/3\u003c/code\u003e builds the trusted job arguments with atom keys (\u003ccode\u003e:primary_key\u003c/code\u003e, \u003ccode\u003e:tenant\u003c/code\u003e, \u003ccode\u003e:action_arguments\u003c/code\u003e) and merges the caller\u0027s \u003ccode\u003e:args\u003c/code\u003e underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so \u003ccode\u003eMap.merge\u003c/code\u003e sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes \u003ccode\u003e:args\u003c/code\u003e as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\u003c/p\u003e\n\u003cp\u003eThis issue affects ash_oban: from 0.2.5 before 0.8.14.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the `:args` option of `AshOban.build_trigger/3` to retarget an update or destroy trigger at another record, including across tenants.\n\n`build_trigger/3` builds the trusted job arguments with atom keys (`:primary_key`, `:tenant`, `:action_arguments`) and merges the caller\u0027s `:args` underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so `Map.merge` sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes `:args` as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\n\nThis issue affects ash_oban: from 0.2.5 before 0.8.14."
}
],
"value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.\n\nbuild_trigger/3 builds the trusted job arguments with atom keys (:primary_key, :tenant, :action_arguments) and merges the caller\u0027s :args underneath so the trusted values win on collision. Because Oban job arguments round-trip through JSON, the caller\u0027s keys arrive as strings, so Map.merge sees no collision and both keys survive. When the job is persisted the JSON object is de-duplicated keeping the last (string) key, and the worker reads the caller\u0027s value. The documentation describes :args as unable to affect the action, so an application that forwards user input into it for uniqueness scoping is exposed to authorization bypass and tenant isolation breaks.\n\nThis issue affects ash_oban: from 0.2.5 before 0.8.14."
}
],
"impacts": [
{
"capecId": "CAPEC-77",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-77 Manipulating User-Controlled Variables"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-30T11:50:21.136Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"tags": [
"vendor-advisory",
"related"
],
"url": "https://github.com/ash-project/ash_oban/security/advisories/GHSA-gj9p-x393-rf9h"
},
{
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-78038.html"
},
{
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-78038"
},
{
"tags": [
"patch"
],
"url": "https://github.com/ash-project/ash_oban/commit/da2d81e1e8e1dcc3e6ec8587cdb4f273575ffca3"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Job argument injection via :args overrides primary_key and tenant in AshOban"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-78038",
"datePublished": "2026-08-30T11:50:21.136Z",
"dateReserved": "2026-08-28T19:30:02.318Z",
"dateUpdated": "2026-08-31T14:55:17.264Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
- If available, use features of the language or framework that allow specification of allowlists of attributes or fields that are allowed to be modified. If possible, prefer allowlists over denylists.
- For applications written with Ruby on Rails, use the attr_accessible (allowlist) or attr_protected (denylist) macros in each class that may be used in mass assignment.
Mitigation
If available, use the signing/sealing features of the programming language to assure that deserialized data has not been tainted. For example, a hash-based message authentication code (HMAC) could be used to ensure that data has not been modified.
Mitigation
Strategy: Input Validation
For any externally-influenced input, check the input against an allowlist of internal object attributes or fields that are allowed to be modified.
Mitigation
Strategy: Refactoring
Refactor the code so that object attributes or fields do not need to be dynamically identified, and only expose getter/setter functionality for the intended attributes.
No CAPEC attack patterns related to this CWE.