CVE-2026-48575
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVSS
7.9
Alto
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-693
0.3%EPSS · 30 días0.3%
2026-08-122026-09-09
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-796385.3 MED—
——0Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.1dCVE-2026-878084.9 MED—
——0SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (commit d5e2d0bc) added an administrator check for SQL mode (method=2) in POST /api/search/fullTextSearchBlock, but the endpoint still does not enforce the application's read-only boundary: for method=2 it forwards caller-supplied SQL to the blocks database query path without calling model.CheckReadonly or CheckReadonlyStatementInBox. As a result, when a workspace runs in read-only mode (--readonly=true), an authenticated administrator can submit arbitrary SQL through /api/search/fullTextSearchBlock and obtain raw read access to the blocks database, even though the dedicated /api/query/sql endpoint is blocked in that mode. Fixed in v3.8.2.1dCVE-2026-785526.0 MED25.8%
——8The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.2dCVE-2026-286647.8 ALT0.2%
——0In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.2dCVE-2026-813769.6 CRÍ49.6%
——15Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.2dCVE-2026-778926.8 MED23.7%
——7No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.2d