Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-87899 — cPanel Arbitrary Code Execution via Privilege Escalation

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

Remote | Authorization
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
9.4 CRITICAL
CVE-2026-87898 — Plesk OS Command Injection Vulnerability

OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.5 HIGH
CVE-2026-86065 — Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, p…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket cl…

Remote | Denial of Service
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
8.6 HIGH
CVE-2026-86064 — Klever-Go: /log controls global node logging

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.g…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.2 HIGH
CVE-2026-85475 — Automation-controller: automation-controller-container: automation-controller: rsyslog co…

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, L…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.6 MEDIUM
CVE-2026-84724 — Automation-controller: automation-controller: systemjob extra_vars.days argument injectio…

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable with…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.4 MEDIUM
CVE-2026-84721 — Automation-controller: automation-controller: email notification backend allows ssrf via …

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a …

ansible_automation_platform | Remote | Server-Side Request Forgery
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-84720 — Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks pr…

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between w…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
9.9 CRITICAL
CVE-2026-84719 — Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy saniti…

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template,…

ansible_automation_platform | Remote | Authorization
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
4.3 MEDIUM
CVE-2026-84718 — Automation-controller: automation-controller: client ip spoofing in audit/access logs via…

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's c…

ansible_automation_platform | Remote | Misconfiguration
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-84717 — Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbuc…

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events aft…

ansible_automation_platform | Remote | Authentication
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.6 MEDIUM
CVE-2026-84716 — Automation-controller: automation-controller: instance install_bundle issues 10-year, non…

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the c…

ansible_automation_platform | Remote | Authentication
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
7.1 HIGH
CVE-2026-84714 — Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows ji…

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but…

ansible_automation_platform | Remote | Injection
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
6.5 MEDIUM
CVE-2026-84713 — Automation-controller: automation-controller: notification.recipients/subject/error lack …

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, it…

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
5.3 MEDIUM
CVE-2026-84712 — Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses aut…

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated …

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
7.6 HIGH
CVE-2026-84706 — Automation-controller: automation-controller-container: automation-controller: credential…

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix che…

ansible_automation_platform | Remote | Misconfiguration
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-84691 — Automation-controller: automation-controller-container: automation-controller: format str…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-stri…

ansible_automation_platform | Remote | Information Disclosure
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.7 HIGH
CVE-2026-84683 — Automation-controller: automation-controller-container: automation-controller: stored cro…

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacter…

ansible_automation_platform | Remote | Cross-Site Scripting
Sep 23, 2026 Sep 24, 2026
Sep 23, 2026
Sep 24, 2026
8.4 HIGH
CVE-2026-82409 — Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elastics…

Remote | Injection
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
7.0 HIGH
CVE-2026-82407 — Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liven…

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKe…

Remote | Misconfiguration
Sep 23, 2026 Sep 23, 2026
Sep 23, 2026
Sep 23, 2026
Showing 20 of 14292 Results