PULSE
FEED
ransomumbra reclama a SANAtech Global Solutions · Technologyransomumbra reclama a Raqib · Technologyransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomumbra reclama a SANAtech Global Solutions · Technologyransomumbra reclama a Raqib · Technologyransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Services
← Todos los CVEs
CVE Watch7 oct 2026

CVE-2026-106471

A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated paramet

CVSS

8.1

Alto

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 7 oct 2026 · Última mod.: 7 oct 2026 · CWE-863

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization checks on subsequent objects. When target resource identifiers are known, this can enable unauthorized disclosure of consumer information and unauthorized modification of entitlements and related subscription resources, including across organizations.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-81535—
—
———In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.13h
CVE-2026-97626—
—
——0Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.18h
CVE-2026-97208—
—
——0The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web interface enforces. A repository administrator could therefore create new push mirrors on instances where the site administrator had disabled them. A push mirror pushes all refs of the repository to a remote chosen by the caller, on each commit or on a schedule.18h
CVE-2026-89182—
—
——0With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository created by push. Any user who can create repositories could make their new repository public in violation of the instance policy. The default configuration is not affected.18h
CVE-2026-86684—
—
——0The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository administrator who is not allowed to import local paths could add a push mirror to a local path on the server when the repository owner has that permission. Gitea then pushed the repository's refs into an existing Git repository at that path with the permissions of the Gitea process.18h
CVE-2026-1064987.7 ALT
—
——0Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.18h