CVE-2026-89242
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode
CVSS
7.2
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 11, 2026 · Last modified: Sep 11, 2026 · CWE-918
Not enough EPSS history yet.
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files or access internal services, with results parsed as login credentials.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-19486——
——0A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token.
This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.9hCVE-2026-820978.8 HIG—
——0IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.9hCVE-2026-812657.5 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.5.9hCVE-2026-812138.6 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.9hCVE-2026-812078.5 HIG—
——0IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).9hCVE-2026-797235.0 MED—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.9h