CVE-2026-35533
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a lo
CVSS
7.7
Alto
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Publicado: 7 abr 2026 · Última mod.: 24 jul 2026 · CWE-284
0.2%EPSS · 30 días0.2%
2026-07-032026-07-30
mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and then reach dangerous directives such as [env] _.source, templates, hooks, or tasks.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-453776.5 MED—
———Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without authentication by anyone who obtains it. This is because Decidim::DownloadYourDataController#download_file authenticates the export owner but redirects to a signed Active Storage blob URL that is no longer bound to the owner session. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.1hCVE-2026-653115.3 MED—
——0The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's logging level and target without requiring
authentication. A remote, unauthenticated attacker with network
access to the service may suppress audit logging, potentially
concealing other activity on the system.7hCVE-2026-148346.5 MED—
——0The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.4hCVE-2026-580393.3 BAJ—
——0A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths.
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.8hCVE-2026-622468.5 ALT—
——0Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.1dCVE-2026-6680310.0 CRÍ—
——0Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.20h