Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- Rapid7 VelociraptorCVE-2026-85737Low-privilege analyst reads arbitrary server files via ungated `sql()` VQL plugin (no permission check, CA private key disclosed)6.5 · Medium
- ChartbrewCVE-2026-85295Full account takeover via JWTs signed with the static default `CB_SECRET` (four auth middlewares fall back to the publicly known key `change_to_random_string`)9.8 · Critical
- ChartbrewCVE-2026-85712Cross-tenant project takeover via IDOR in `checkPermissions` (`team_id` resolved from the JSON body instead of the project's ownership)8.8 · High
- ChartbrewCVE-2026-85726Blind NoSQL injection via unescaped date variable in shared charts (`applyMongoVariables` inserts `date` values with no escaping into MongoDB query strings)7.5 · High
- ChartbrewCVE-2026-85708Private chart data disclosure via forgeable share tokens signed with the static default `CB_SECRET` (no visibility check, enumeration via sequential integer IDs)7.5 · High
- ChartbrewCVE-2026-85736Arbitrary file deletion as root via data connection SSL/SSH path fields (`removeConnection` calls `fs.unlink` on four user-controllable paths with no restriction)8.1 · High
- ProwlerCVE-2026-73263Remote code execution on the shared Celery workers via a kubeconfig with a legacy `auth-provider` `cmd-path` (the validator only blocks `exec` blocks)9.9 · Critical
- GoCDCVE-2026-68919Stored XSS via a commit message shaped as package material JSON (`materials_helper.rb` classifies by a regex on the comment text instead of the material type)7.0 · High
- ntopngCVE-2026-82412Remote code execution via OS command injection in the `scan_ports` parameter of the vulnerability-scan REST API, reachable by any authenticated account down to the lowest read-only role8.8 · High
- seerrCVE-2026-73291Path traversal to remote code execution via the avatar proxy cache filename built from the media server's `ETag` (`path.join` collapses `../`, overwrites `/app/dist/index.js`)7.1 · High
- OpenWrtCVE-2026-62947ACL bypass and arbitrary root file read via `cgi-download` (missing path canonicalization, `fnmatch` without `FNM_PATHNAME`)4.9 · Medium
- Joplin ServerCVE-2026-59814Stored XSS via an inline-served attachment on a publicly shared note (attacker-controlled `Content-Type`, missing CSP `script-src`/`nosniff`); escalates to full admin access against a logged-in administrator7.6 · High
- OpencastCVE-2026-77614Session fixation enables account takeover via a crafted link (`JSESSIONID` is not rotated on login and an id supplied via `;jsessionid=` is adopted)8.8 · High
- OpencastCVE-2026-77615Stored XSS in the Paella player via caption cues (WebVTT/DFXP cue text reaches the DOM via `innerHTML` without escaping)8.7 · High
- OPNsenseCVE-2026-58390Stored XSS via OpenVPN `common_name` (RADIUS/LDAP) in the status views → code execution in the root admin session, escalating to root RCE8.0 · High
- ApostropheCMSCVE-2026-63667Arbitrary read of allow-listed-extension files via the attachment path built from the archive JSON in the `@apostrophecms/import-export` module (the `../` guard only checks tar entries, not the JSON fields)6.5 · Medium
- MalcolmCVE-2026-55676Authenticated RCE via unrestricted `.php` upload in the file-upload component (empty allowlist)8.8 · High
- CronicleCVE-2026-55562Stored XSS in the `full_name` field of the Activity Log → code execution in the admin session9.0 · Critical
- TautulliCVE-2026-45381Reflected XSS in the `/search` `query` parameter (incomplete escaping) → API key theft7.4 · High
- GraylogCVE-2026-69190Manager-to-Owner privilege escalation via the `share_request` field of `PUT /api/views/{id}` (the update path checks `view:edit` instead of ownership) → deletion of other users' dashboards6.3 · Medium
Coordinated Disclosure
turingpoint follows the principle of coordinated disclosure: vulnerabilities we find are first reported confidentially to the affected vendor and only documented publicly once a patch is available. This gives users the opportunity to secure their systems before technical details become known.
This Expertise for Your Software
Our team finds critical vulnerabilities in production software before attackers do. Have your applications tested by the same specialists, with a penetration test from turingpoint.
