CVE-2025-10939
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a pro
CVSS
3.7
Low
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Published: Oct 28, 2025 · Last modified: Aug 31, 2026 · CWE-427
0.4%EPSS · 30 days0.4%
2026-08-232026-09-20
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:21370
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:21371
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-10939
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2398025
- github.comhttps://github.com/keycloak/keycloak/issues/43763
- github.comhttps://github.com/keycloak/keycloak/pull/43765
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-549168.8 HIG35.4%
——11NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definitions_test.py executes from git import Git, Repo, or add tests/conftest.py for automatic collection-time execution. Python imports and runs the pull-request module before any test function, allowing arbitrary code execution on the GitHub Actions runner, test-result tampering, and access to tokens or network resources exposed to the workflow. This module-shadowing path is independent of the earlier pickle deserialization flaw and the separately tracked NETBOX_DT_LIBRARY_URL issue. This vulnerability is fixed by commit b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037.3dCVE-2026-567958.2 HIG2.8%
——1Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.2dCVE-2026-928387.8 HIG3.6%
——1A DLL hijacking
vulnerability exists in the GeoVision GV-Remote E-Map desktop
application. The application loads one or more dynamic-link libraries (DLLs)
from an unsafe search path, allowing a local attacker to place a malicious DLL
in a location searched before the legitimate library location. If
successfully exploited, an attacker with local write access to the affected
directory could achieve arbitrary code execution in the security context of
the GV-Remote E-Map process.3dCVE-2026-921807.8 HIG3.9%
——1pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.5dCVE-2026-689557.8 HIG7.9%
——2The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.5dCVE-2026-875308.1 HIG3.3%
——1Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)12d