CVE-2026-0418
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper wit
CVSS
4.5
Medio
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-15 · CWE-610
0.2%EPSS · 30 días0.2%
2026-07-022026-07-30
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local network to tamper with the system.
- kb.netgear.comhttps://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisory
- www.netgear.comhttps://www.netgear.com/support/product/cbr750/
- www.netgear.comhttps://www.netgear.com/support/product/ex6120/
- www.netgear.comhttps://www.netgear.com/support/product/ex6130/
- www.netgear.comhttps://www.netgear.com/support/product/mr60/
- www.netgear.comhttps://www.netgear.com/support/product/mr70/
- www.netgear.comhttps://www.netgear.com/support/product/mr80/
- www.netgear.comhttps://www.netgear.com/support/product/ms60/
- www.netgear.comhttps://www.netgear.com/support/product/ms70/
- www.netgear.comhttps://www.netgear.com/support/product/ms80/
- www.netgear.comhttps://www.netgear.com/support/product/rax15/
- www.netgear.comhttps://www.netgear.com/support/product/rax20/
- www.netgear.comhttps://www.netgear.com/support/product/rax200/
- www.netgear.comhttps://www.netgear.com/support/product/rax35v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax38v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax40v2/
- www.netgear.comhttps://www.netgear.com/support/product/rax42/
- www.netgear.comhttps://www.netgear.com/support/product/rax43/
- www.netgear.comhttps://www.netgear.com/support/product/rax45/
- www.netgear.comhttps://www.netgear.com/support/product/rax48/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-565675.1 MED—
———HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.6hCVE-2026-685626.2 MED—
——0A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.10hCVE-2026-553907.5 ALT28.8%
——9datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.1dCVE-2026-553897.5 ALT28.9%
——9datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to the input directory and without honoring --no-allow-remote-refs, allowing arbitrary local file reads. This issue is fixed in version 0.62.0.1dCVE-2026-464858.2 ALT22.8%
——7Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8.11dCVE-2026-155838.6 ALT39.5%
——12A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.16d