CVE-2026-17529
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent
CVSS
6.3
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 27 jul 2026 · Última mod.: 27 jul 2026 · CWE-285 · CWE-863
Sin historial EPSS suficiente todavía.
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is d23011262e8e75e1ec41b0f1f0091493a022327e. It is suggested to install a patch to address this issue.
- github.comhttps://github.com/AstrBotDevs/AstrBot/
- github.comhttps://github.com/AstrBotDevs/AstrBot/commit/d23011262e8e75e1ec41b0f1f0091493a022327e
- github.comhttps://github.com/AstrBotDevs/AstrBot/issues/8780
- github.comhttps://github.com/AstrBotDevs/AstrBot/pull/8786
- vuldb.comhttps://vuldb.com/cve/CVE-2026-17529
- vuldb.comhttps://vuldb.com/submit/862512
- vuldb.comhttps://vuldb.com/vuln/383394
- vuldb.comhttps://vuldb.com/vuln/383394/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-420168.1 ALT—
———JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.4hCVE-2026-64642——
———Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.7hCVE-2026-17568——
———Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.
This issue affects :
* Devolutions Server 2026.2.4.0 through 2026.2.12.0
* Devolutions Server 2026.1.23.0 and earlier4hCVE-2026-175315.0 MED—
———A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.4hCVE-2026-175306.3 MED—
———A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.4hCVE-2026-596898.0 ALT—
———An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.11h