CVE-2026-58211
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client coul
CVSS
5.4
Medio
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 8 jul 2026 · Última mod.: 9 jul 2026 · CWE-863
0.2%EPSS · 30 días0.3%
2026-08-102026-09-06
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-865448.1 ALT—
———knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.12hCVE-2026-864377.2 ALT—
———Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.13hCVE-2026-864987.7 ALT—
———In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission18hCVE-2026-864936.5 MED—
———In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards18hCVE-2026-864906.5 MED—
———In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint18hCVE-2026-864873.1 BAJ—
———In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content18h