CVE-2026-20498
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privileg
CVSS
—
Sin CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 3 ago 2026 · Última mod.: 3 ago 2026 · CWE-1287
Sin historial EPSS suficiente todavía.
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-47738.1 ALT24.4%
——7Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass.
This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.12dCVE-2026-505247.5 ALT46.9%
——14Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.12dCVE-2026-450699.1 CRÍ14.8%
——4Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.19dCVE-2026-551245.5 MED34.7%
——10Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.18dCVE-2026-449359.9 CRÍ33.9%
——10Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.28dCVE-2026-442498.1 ALT44.1%
——13Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.4d