CVE-2026-19424
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can mo
CVSS
7.5
High
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Aug 11, 2026 · Last modified: Aug 26, 2026 · CWE-639
0.4%EPSS · 30 days0.4%
2026-08-262026-09-23
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-783104.3 MED—
———Authorization Bypass Through User-Controlled Key in DIAEnergie.
This issue affects DIAEnergie: before 1.11.00.022.47mCVE-2026-87739——
———An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and gain unauthorized access to sensitive information.47mCVE-2026-936612.7 LOW—
———The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.3hCVE-2026-890042.7 LOW—
———The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.3hCVE-2026-828494.3 MED—
———The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.3hCVE-2026-967627.3 HIG—
———A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.14h