CVE-2026-82813
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken
CVSS
5.4
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 31, 2026 · Last modified: Aug 31, 2026 · CWE-345
Not enough EPSS history yet.
A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
- github.comhttps://github.com/xryj920/chrome_extensions/blob/main/BEN%20Group%2C%20Inc.%20TubeBuddy%20for%20YouTube%205.8.4%20allows%20authentication%20token%20overwrite%20through%20an%20unauthenticated%20redirect%20URL%20handler
- vuldb.comhttps://vuldb.com/cve/CVE-2026-82813
- vuldb.comhttps://vuldb.com/submit/875303
- vuldb.comhttps://vuldb.com/vuln/397231
- vuldb.comhttps://vuldb.com/vuln/397231/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-828115.4 MED—
———A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.2hCVE-2026-828589.8 CRI8.5%
——3@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.9hCVE-2026-19410—9.5%
——3An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.
This vulnerability was patched on 24 June 2026, and no customer action is needed.1hCVE-2026-825498.3 HIG8.2%
——2A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly available and might be used.3hCVE-2026-824655.3 MED7.6%
——2pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowing an unauthenticated attacker to submit an unsigned LogoutRequest with a guessed identifier (e.g., an email address used as NameID) to terminate a victim's SAML session.2dCVE-2026-824626.5 MED3.2%
——1pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.2d