PULSE
FEED
ransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcareransomthreeam reclama a safescaffolding.net · GB · Manufacturingransomthreeam reclama a coosalud.com · CO · Healthcareransomthreeam reclama a pistonespersan.com.ar · AR · Manufacturingransomthreeam reclama a midwestbit.com · US · Technologyransomthreeam reclama a apexus.com · US · Technologyransomthreeam reclama a bhn-expertise.com · DE · Professional Servicesransomthreeam reclama a stjames.wa.edu.au · AU · Educationransomdoommageddon reclama a Goodrich Logistics · Transportationransomdoommageddon reclama a Chem Process Systems Pvt. Ltd. · IN · Manufacturingransomplay reclama a Starr Whitehouse Landscape Architects · US · Professional Servicesransomplay reclama a Ever Ready First Aid · US · Healthcareransommedusalocker reclama a PKSF — Palli Karma-Sahayak Foundation · BD · Financial Servicesransomemperador reclama a Amazon Informatica · BR · Technologyransomqilin reclama a New World Diagnostics · PH · Healthcare
← Todos los CVEs
CVE Watch28 sept 2026

CVE-2026-97335

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 an

CVSS

7.7

Alto

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-863

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any other project on the server, including its snapshots and configuration. The client does this with a crafted request that sets a source volume and source.project but omits source.type.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1011392.7 BAJ
—
———A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.5h
CVE-2026-86102—
—
———An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.5h
CVE-2026-19759—
—
———An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type. This vulnerability was patched on 17 June 2026, and no customer action is needed.13h
CVE-2026-823789.0 CRÍ
—
———Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an unsigned authorization request. The endpoint derives the authorizing identity from a request-supplied value rather than the authenticated session. Only installations that configure an OAuth 1.0a site-wide consumer are affected, and exploitation requires knowledge of one of its outstanding request tokens. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which binds authorization to the logged-in session.9h
CVE-2026-1010064.3 MED
—
———A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_requests/get_attendance_requests of the file hrms/api/__init__.py of the component Permission Validation. This manipulation of the argument employee causes incorrect authorization. Remote exploitation of the attack is possible. The vendor replied: "This issue has already been reported by another individual, and based on that, we have fixed it."9h
CVE-2026-10100010.0 CRÍ
—
———A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.9h