CVE-2026-67970
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path
CVSS
7.5
Alto
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 3 ago 2026 · Última mod.: 6 ago 2026 · CWE-284
0.1%EPSS · 30 días0.2%
2026-08-042026-08-24
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-614197.8 ALT—
——0Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.1dCVE-2026-782457.3 ALT—
——0A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.2dCVE-2026-782027.3 ALT20.7%
——6A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.2dCVE-2026-76609—14.8%
——4Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.2dCVE-2026-76608—21.5%
——6Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.2dCVE-2026-76607—14.8%
——4Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.2d