CVE-2026-16209
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py o
CVSS
7.3
High
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Published: Jul 19, 2026 · Last modified: Jul 20, 2026 · CWE-287 · CWE-306
0.4%EPSS · 30 days0.4%
2026-07-192026-07-20
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is bd4891c60315f17611a3b7a651ffe0fba7cfe71e. Applying a patch is advised to resolve this issue.
- github.comhttps://github.com/Gerapy/Gerapy/
- github.comhttps://github.com/Gerapy/Gerapy/commit/bd4891c60315f17611a3b7a651ffe0fba7cfe71e
- github.comhttps://github.com/Gerapy/Gerapy/issues/317
- github.comhttps://github.com/Gerapy/Gerapy/pull/319
- vuldb.comhttps://vuldb.com/cve/CVE-2026-16209
- vuldb.comhttps://vuldb.com/submit/857926
- vuldb.comhttps://vuldb.com/vuln/380025
- vuldb.comhttps://vuldb.com/vuln/380025/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-32489.8 CRI100.0%
KEV—80Langflow Missing Authentication Vulnerability6dCVE-2024-116809.8 CRI99.8%
KEV—80ProjectSend Improper Authentication Vulnerability6dCVE-2026-561645.3 MED92.1%
KEV—78Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability6dCVE-2026-468179.8 CRI60.4%
KEV—68Oracle E-Business Suite Improper Privilege Management Vulnerability5dCVE-2023-278239.8 CRI98.9%
——30An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.12dCVE-2022-245629.8 CRI98.9%
——30In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.12d