PULSE
LIVE75signals / 24h
FEED
ransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomorova reclama a David King Architect · US · Professional Servicesransomorova reclama a Woodside Ranch · US · Agriculture and Food Productionransombarracuda reclama a Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson · Healthcareransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomdragonforce reclama a Primary Eye Care · US · Healthcareransomorova reclama a St Theresa Catholic Church · US · Otherransomorova reclama a Stoneybrook West Master Association, Inc · US · Otherransomorova reclama a Stonecrest POA · US · Otherransomqilin reclama a Bloom Financials · GB · Financial Servicesransomorova reclama a Magnolia Dental · US · Healthcareransomorova reclama a Country Oaks Veterinary Clinic · US · Healthcareransomorova reclama a David King Architect · US · Professional Servicesransomorova reclama a Woodside Ranch · US · Agriculture and Food Productionransombarracuda reclama a Ferrell \ Skyline Implants & Periodontics \ Dr. Scott Ferguson · Healthcareransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitality
← All CVEs
CVE WatchAug 5, 2026

CVE-2026-71277

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, a

CVSS

9.1

Critical

EPSS

KEV

Exploit Today

0-100

Published: Aug 5, 2026 · Last modified: Aug 5, 2026 · CWE-287

EPSS · 30d

Not enough EPSS history yet.

Technical description

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-189907.3 HIG
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.7h
CVE-2026-91929.8 CRI
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.15h
CVE-2026-160557.5 HIG
0The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.19h
CVE-2026-160367.5 HIG
0The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.18h
CVE-2026-153727.5 HIG
0The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.18h
CVE-2026-152109.1 CRI
0The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.18h