CVE-2026-60135
An attacker can modify data that should be restricted to read‑only access.
CVSS
6.5
Medium
EPSS
0.2%
p12
KEV
—
Exploit Today
4
0-100
Published: Jul 24, 2026 · Last modified: Jul 30, 2026 · CWE-286
0.2%EPSS · 30 days0.2%
2026-07-252026-07-29
An attacker can modify data that should be restricted to read‑only access.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-564288.1 HIG—
———The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.8hCVE-2024-292965.3 MED66.2%
——20A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.22d