CVE-2026-36028
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions
CVSS
6.8
Medium
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Jul 8, 2026 · Last modified: Jul 9, 2026 · CWE-288
0.2%EPSS · 30 days0.3%
2026-08-082026-09-04
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-761697.5 HIG42.8%
——13fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.2dCVE-2026-629169.1 CRI45.6%
——14Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.1dCVE-2026-847777.4 HIG14.9%
——4Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.2dCVE-2026-811683.7 LOW26.3%
——8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.3dCVE-2026-166474.1 MED8.9%
——3Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.1dCVE-2026-822257.4 HIG14.9%
——4Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.4d