CVE-2026-58424
Permanent Fork PR Workflow Approval Gate Bypass
CVSS
8.9
High
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Published: Jul 3, 2026 · Last modified: Jul 6, 2026 · CWE-285 · CWE-732 · CWE-863
0.2%EPSS · 30 days0.4%
2026-08-222026-09-19
Permanent Fork PR Workflow Approval Gate Bypass
- blog.gitea.comhttps://blog.gitea.com/release-of-1.26.3-and-1.26.4/
- github.comhttps://github.com/go-gitea/gitea/pull/38010
- github.comhttps://github.com/go-gitea/gitea/releases/tag/v1.26.4
- github.comhttps://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486
- github.comhttps://github.com/go-gitea/gitea/security/advisories/GHSA-777r-4v59-6486
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-12424.3 MED7.5%
——2The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass authorization checks and create arbitrary posts.11hCVE-2026-924033.7 LOW3.4%
——1The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresponds to the form that was rendered to the visitor, allowing unauthenticated users to submit against a different registered form and modify the title and content of the post that form is bound to.11hCVE-2026-842418.1 HIG22.8%
——7IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.11hCVE-2026-840767.6 HIG23.9%
——7IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.10hCVE-2026-840367.4 HIG17.6%
——5IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.10hCVE-2026-115405.3 MED23.1%
——7IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.10h