CVE-2026-77483
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-1390
Not enough EPSS history yet.
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-730259.8 CRI—
———Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.3hCVE-2026-628958.8 HIG—
———Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.3hCVE-2026-802198.7 HIG—
——0A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt.2hCVE-2026-738199.8 CRI42.8%
——13The affected Ebyte
product's vendor configuration utility permits access to administrative
functions without verifying the operator's identity under certain
credential conditions. An unauthenticated attacker on the adjacent
network could modify critical settings or change access credentials,
potentially preventing legitimate administrators from managing the
device.7dCVE-2026-650988.1 HIG49.7%
——15NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.7dCVE-2026-680679.8 CRI23.9%
——7The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.7d