CVE-2025-22426
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could l
CVSS
7.8
Alto
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-284
0.1%EPSS · 30 días0.1%
2026-06-302026-07-23
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-65758——
——0The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.8hCVE-2026-65757—2.8%
——1The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.8hCVE-2026-64876—2.8%
——1Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.8hCVE-2026-64871—2.8%
——1Administrator URL purges did not consistently require a valid token and cache-management permission.8hCVE-2024-583307.5 ALT39.9%
——12A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.9hCVE-2026-64796—9.0%
——3Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.21h