Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- SEP sesampendingUnauthenticated remote root code execution: the `executeSql` REST endpoint (TCP 11401, no authentication by default) compiles a `RYTHM` `template` expression to Java bytecode and runs it as root10.0 · Critical
- Collax Security GatewaypendingOS command injection with no precondition: a delegated `mailadmin` injects via the hold action `refvalue` and reaches execution as `admin`, then root9.9 · Critical
- Collax Security GatewaypendingOS command injection: a delegated `proxyadmin` injects via the Squid rule tester `plain` fields `url`/`username` and reaches execution as `admin`, then root9.9 · Critical
- Collax Security GatewaypendingAnonymous reflected SVG XSS: the `c` parameter of `generate-logo.cgi` reaches an active `image/svg+xml` document raw9.3 · Critical
- Collax Security GatewaypendingAnonymous reflected XSS: `ui` and `from` are reflected without `ESCAPE=HTML` into the login page of both origins, enabling credential harvesting9.3 · Critical
- Collax Security GatewaypendingAnonymous reflected XSS: `webaccess.cgi` serialises `%ENV` into an inline `<script>` block and does not escape the wrapping single quote9.3 · Critical
- Collax Security GatewaypendingOS command injection: a delegated `mailadmin` overwrites the client-side queue `id` in held-mail release and reaches execution as `admin`, then root8.5 · High
- Collax Security GatewaypendingCSRF on `rrd2csv.cgi` (`eval "require $plugin"`, no CSRF token, no SameSite) reaches code execution as `admin` and root via setuid `suwrap`8.3 · High
- Collax Security GatewaypendingStored XSS: an unauthenticated SMTP sender sets an envelope sender the held-mail queue `Html` cell renderer writes as innerHTML8.0 · High
- Collax Security GatewaypendingStored XSS: a layer 2 neighbour sends an LLDP frame whose typeless `<display>` field renders as raw innerHTML in the qooxdoo rich label7.4 · High
- Collax Security GatewaypendingAnonymous deletion of the 2FA token store via path traversal in the logout cookie (`->new(sprintf)` instead of `->child`), plus an existence oracle for arbitrary paths7.3 · High
- TeableCVE-2026-104100Path traversal in the `hash` parameter of the attachment presign API: a self-registered account writes and overwrites arbitrary files in the container as root8.8 · High
- Feathernot requestedArbitrary file write via the unconfirmed `feather://install/` deep link: the unchecked Zip library lets `../../` entries overwrite `Documents/` and `Library/`Moderate
- Mastodon iOSpendingOAuth bearer token of the signed-in account is sent to an attacker-controlled host as soon as the "Open in Mastodon" share action fails to resolve an ordinary web page as a Mastodon item7.1 · High
- Rapid7 VelociraptorCVE-2026-85737Low-privilege analyst reads arbitrary server files via ungated `sql()` VQL plugin (no permission check, CA private key disclosed)6.5 · Medium
- ChartbrewCVE-2026-85295Full account takeover via JWTs signed with the static default `CB_SECRET` (four auth middlewares fall back to the publicly known key `change_to_random_string`)9.8 · Critical
- ChartbrewCVE-2026-85712Cross-tenant project takeover via IDOR in `checkPermissions` (`team_id` resolved from the JSON body instead of the project's ownership)8.8 · High
- ChartbrewCVE-2026-85726Blind NoSQL injection via unescaped date variable in shared charts (`applyMongoVariables` inserts `date` values with no escaping into MongoDB query strings)7.5 · High
- ChartbrewCVE-2026-85708Private chart data disclosure via forgeable share tokens signed with the static default `CB_SECRET` (no visibility check, enumeration via sequential integer IDs)7.5 · High
- ChartbrewCVE-2026-85736Arbitrary file deletion as root via data connection SSL/SSH path fields (`removeConnection` calls `fs.unlink` on four user-controllable paths with no restriction)8.1 · High
Coordinated Disclosure
turingpoint follows the principle of coordinated disclosure: vulnerabilities we find are first reported confidentially to the affected vendor and only documented publicly once a patch is available. This gives users the opportunity to secure their systems before technical details become known.
This Expertise for Your Software
Our team finds critical vulnerabilities in production software before attackers do. Have your applications tested by the same specialists, with a penetration test from turingpoint.
