PULSE
FEED
ransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Services
← All CVEs
CVE WatchOct 8, 2026

CVE-2026-4894

A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multi

CVSS

—

No CVSS

EPSS

0.4%

p30

KEV

—

Exploit Today

9

0-100

Published: Oct 8, 2026 · Last modified: Oct 8, 2026 · CWE-290

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext authentication process, which allows multiple email addresses to be accepted by manipulating the email field in the /api/method/press.api.account.signup endpoint. The vulnerability occurs when an unauthenticated remote attacker adds more than one email address. The service processes the entire value as a valid list of recipients and sends the OTP code to all addresses without proper validation of all added emails (only one of them needs to be valid). Exploiting this vulnerability would allow an attacker to: * Obtain the authentication OTP; * Impersonate someone else in the registration process; * Register accounts using other people's email addresses without access to the mailbox; * Indirectly confirm the existence of already registered email addresses.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1073366.5 MED
—
——0Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.12h
CVE-2026-1075897.5 HIG
—
——0Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.13h
CVE-2026-87663—
53.0%
——16An authentication bypass and command injection vulnerability exists in the inter-switch remote execution service of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing remote command execution IPC frames across the fabric, the receiving switch processes these commands at an elevated processing level without proper verification of transmitted parameters. This allows an attacker on a single fabric-connected switch to escalate privileges and execute arbitrary root commands locally or across other managed fabric members where remote execution functionality is enabled.5h
CVE-2026-87686—
9.1%
——3An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal management VLAN trust decisions using the client-supplied HTTP host header instead of the actual socket transport layer source IP address. Successful exploitation allows the attacker to bypass IP-filtering access control lists (ACLs) and obtain sensitive device metadata (such as model, serial number, hardware revision, and firmware version) without authentication.13h
CVE-2026-87670—
2.8%
——1An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST API gateway. The internal gate guarding restricted management endpoints relies exclusively on client-controlled HTTP headers. An authenticated user with any valid REST session can spoof these headers to gain unauthorized access to internal management endpoints. This allows low-privilege users to view sensitive chassis metadata, hardware memory patrolling state, and firmware integrity audit logs.13h
CVE-2026-92542—
0.0%
——0The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to13h