Common Vulnerabilities and Exposures (CVE)

CVE-2026-100626

Sep 26, 2026 23:01:57 UTC

capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply arbitrary paths in the private images buck...

CVE-2026-72662

Sep 26, 2026 23:01:33 UTC

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user grant...

CVE-2026-78582

Sep 26, 2026 23:01:13 UTC

Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding Synthetics privileges scoped to a single Kib...

CVE-2026-82294

Sep 26, 2026 23:00:58 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).

CVE-2026-82300

Sep 26, 2026 23:00:43 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).

CVE-2026-94398

Sep 26, 2026 23:00:24 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94399

Sep 26, 2026 23:00:09 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94400

Sep 26, 2026 22:59:48 UTC

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94396

Sep 26, 2026 22:59:33 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94397

Sep 26, 2026 22:59:19 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94408

Sep 26, 2026 22:59:01 UTC

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

CVE-2026-94130

Sep 26, 2026 22:58:35 UTC

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.

CVE-2026-94132

Sep 26, 2026 22:58:17 UTC

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so a...

CVE-2026-94131

Sep 26, 2026 22:57:55 UTC

Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 - A subscriber could store a path in a file-type custom field and have AcyMailing delete that file when the field was cl...

CVE-2026-97160

Sep 26, 2026 22:57:33 UTC

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29