CVE-2026-39429
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3,
CVSS
8.2
Alto
EPSS
0.4%
p36
KEV
—
Exploit Today
11
0-100
Publicado: 8 abr 2026 · Última mod.: 24 jul 2026 · CWE-302 · CWE-862
0.4%EPSS · 30 días0.4%
2026-07-082026-08-05
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-5423——
———@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.
Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.7hCVE-2026-182777.1 ALT—
———Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path7hCVE-2026-182764.3 MED—
———Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check7hCVE-2026-667127.5 ALT—
———Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.7hCVE-2026-667088.2 ALT—
———Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.8hCVE-2026-667015.3 MED—
———Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.8h