PULSE
FEED
ransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomlamashtu reclama a GERLON · DE · Not Foundransomrhysida reclama a clicks digital GmbH Information · DE · Technologyransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomlamashtu reclama a Vinco Energy · US · Energy & Utilitiesransomlamashtu reclama a Becker Logistik · DE · Transportationransomlamashtu reclama a Wilhelm Kühne · DE · Manufacturingransomlamashtu reclama a FIDUCIAL · FR · Financial Servicesransomlamashtu reclama a Virtual Ideas · AU · Technologyransomlamashtu reclama a PROJAHN · DE · Otherransomlamashtu reclama a Altmannshofer Sicherheits-Videotechnik · DE · Manufacturingransomn0n reclama a MCAP — MortgageHub commercial lending platform · CA · Financial Servicesransomlamashtu reclama a GERLON · DE · Not Foundransomrhysida reclama a clicks digital GmbH Information · DE · Technologyransomrhysida reclama a Law Offices of R. David Williams, P.A. · US · Professional Servicesransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Production
← Todos los CVEs
CVE Watch30 sept 2026

CVE-2026-86136

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privil

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 30 sept 2026 · Última mod.: 30 sept 2026 · CWE-22 · CWE-476 · CWE-862

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-972855.4 MED
—
———Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.4h
CVE-2026-972674.3 MED
—
———Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.4h
CVE-2026-972476.5 MED
—
———Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.3h
CVE-2026-972435.4 MED
—
———Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.3h
CVE-2026-972426.8 MED
—
———Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.3h
CVE-2026-972396.5 MED
—
———Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.3h