CVE-2026-58039
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can
CVSS
3.3
Low
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 31, 2026 · Last modified: Jul 31, 2026 · CWE-284
Not enough EPSS history yet.
A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-653115.3 MED—
——0The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's logging level and target without requiring
authentication. A remote, unauthenticated attacker with network
access to the service may suppress audit logging, potentially
concealing other activity on the system.3hCVE-2026-622468.5 HIG—
——0Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.14hCVE-2026-6680310.0 CRI—
——0Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.8hCVE-2026-580437.5 HIG3.4%
——1A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.
This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.8hCVE-2026-152505.3 MED4.8%
——1The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval workflow.21hCVE-2026-142223.8 LOW4.6%
——1The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.17h