CVE-2026-56768
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to by
CVSS
8.8
High
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jun 25, 2026 · Last modified: Jul 14, 2026 · CWE-862
0.4%EPSS · 30 days0.4%
2026-06-302026-07-21
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees.
- github.comhttps://github.com/haiwen/seahub/commit/162cddae0831188d02bb8d451dc2193e197dcc57
- github.comhttps://github.com/haiwen/seahub/commit/b609949cf64ed6a15708d0fb5ea9c179962e23cc
- github.comhttps://github.com/haiwen/seahub/issues/9050
- plus.seafile.comhttps://plus.seafile.com/wiki/publish/seafile-wiki/v5D5/
- www.vulncheck.comhttps://www.vulncheck.com/advisories/seahub-authentication-bypass-in-sharelinkziptaskview-get-method
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-67926.5 MED—
——0Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects FlexCity: from 5.536.0 through 11052026.4hCVE-2026-650079.6 CRI—
——0The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover.5hCVE-2026-13724.3 MED10.5%
——3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor LMS and Elementor plugins without proper authorization.8hCVE-2026-8593—10.9%
——3Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view and modify BI packs and rules4hCVE-2026-141854.3 MED3.2%
——1The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users with subscriber-level access to modify the WPBot WordPress plugin before 8.2.0's configuration.3hCVE-2026-57494—12.5%
——4AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (`/tasks/:id/claim`, `/tasks/:id/result`, `/tasks/:id/complete`, `/tasks/:id/fail`) to claim, complete, or fail tasks assigned to a different agent. Because ordinary authenticated agents can discover agent names through `GET /api/agenticmail/accounts/directory`, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass. Version 0.9.64 contains a fix.19h