Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-84719 — Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy saniti…

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template,…

ansible_automation_platform | Remote | Authorization
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-84718 — Automation-controller: automation-controller: client ip spoofing in audit/access logs via…

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's c…

ansible_automation_platform | Remote | Misconfiguration
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-84717 — Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbuc…

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events aft…

ansible_automation_platform | Remote | Authentication
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.6 MEDIUM
CVE-2026-84716 — Automation-controller: automation-controller: instance install_bundle issues 10-year, non…

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the c…

ansible_automation_platform | Remote | Authentication
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-84714 — Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows ji…

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-84713 — Automation-controller: automation-controller: notification.recipients/subject/error lack …

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, it…

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
5.3 MEDIUM
CVE-2026-84712 — Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses aut…

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated …

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
7.6 HIGH
CVE-2026-84706 — Automation-controller: automation-controller-container: automation-controller: credential…

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix che…

ansible_automation_platform | Remote | Misconfiguration
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-84691 — Automation-controller: automation-controller-container: automation-controller: format str…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-stri…

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-84683 — Automation-controller: automation-controller-container: automation-controller: stored cro…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacter…

ansible_automation_platform | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-82409 — Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elastics…

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.0 HIGH
CVE-2026-82407 — Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liven…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKe…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-82406 — Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. …

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.7 HIGH
CVE-2026-82405 — Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-contro…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking …

Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
9.1 CRITICAL
CVE-2026-75884 — Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in …

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccoun…

ansible_automation_platform | Remote | Authorization
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-68492 — Plesk RESTful API Extension Untrusted Search Path Remote Code Execution Vulnerability

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful A…

Remote | Path Traversal
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-68490 — CalDAV/CardDAV Improper Access Control

Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.

| Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.1 HIGH
CVE-2026-67238 — RabbitMQ: Atom-table exhaustion via reply-to queue name decoding

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, ut…

rabbitmq_server | Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.2 HIGH
CVE-2026-66079 — RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The …

rabbitmq_server | Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
2.3 LOW
CVE-2026-66076 — RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag…

rabbitmq_server | Remote | Authorization
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14342 Results