CVE-2026-11555
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the
CVSS
3.7
Bajo
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 8 jun 2026 · Última mod.: 23 jul 2026 · CWE-266 · CWE-272
0.4%EPSS · 30 días0.4%
2026-07-222026-08-19
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
- vuldb.comhttps://vuldb.com/cve/CVE-2026-11555
- vuldb.comhttps://vuldb.com/submit/834824
- vuldb.comhttps://vuldb.com/vuln/369165
- vuldb.comhttps://vuldb.com/vuln/369165/cti
- www.dlink.comhttps://www.dlink.com/
- www.notion.sohttps://www.notion.so/D-link-DGS-1100-08PD-v1-00-006-3670ed14e5cb80848bc4e3129dfafa29?source=copy_link
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-769996.3 MED—
———A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.5hCVE-2025-622996.6 MED—
———HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.8hCVE-2026-666829.8 CRÍ—
———Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.4hCVE-2025-156899.8 CRÍ—
———Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.5hCVE-2026-118619.6 CRÍ—
——0A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.7hCVE-2026-733909.8 CRÍ—
——0Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.5h