Security Advisories
Real-world vulnerabilities discovered and responsibly disclosed by turingpoint in widely used open-source and enterprise software.
Security Research
Published Advisories
turingpoint conducts active security research on widely used open-source and enterprise software. Many of these vulnerabilities surface directly during penetration tests for our clients. The following findings were identified by us, disclosed to the vendors through coordinated disclosure, and published as CVEs once a patch became available. Security research made in Germany.
Sort by:
Product
CVE
Vulnerability
CVSS
Advisory
- ProwlerCVE-2026-73263Remote code execution on the shared Celery workers via a kubeconfig with a legacy `auth-provider` `cmd-path` (the validator only blocks `exec` blocks)9.9 · Critical
- GoCDCVE-2026-68919Stored XSS via a commit message shaped as package material JSON (`materials_helper.rb` classifies by a regex on the comment text instead of the material type)7.0 · High
- seerrCVE-2026-73291Path traversal to remote code execution via the avatar proxy cache filename built from the media server's `ETag` (`path.join` collapses `../`, overwrites `/app/dist/index.js`)7.1 · High
- OpenWrtCVE-2026-62947ACL bypass and arbitrary root file read via `cgi-download` (missing path canonicalization, `fnmatch` without `FNM_PATHNAME`)4.9 · Medium
- OpencastCVE-2026-77614Session fixation enables account takeover via a crafted link (`JSESSIONID` is not rotated on login and an id supplied via `;jsessionid=` is adopted)8.8 · High
- OpencastCVE-2026-77615Stored XSS in the Paella player via caption cues (WebVTT/DFXP cue text reaches the DOM via `innerHTML` without escaping)8.7 · High
- OPNsenseCVE-2026-58390Stored XSS via OpenVPN `common_name` (RADIUS/LDAP) in the status views → code execution in the root admin session, escalating to root RCE8.0 · High
- ApostropheCMSCVE-2026-63667Arbitrary read of allow-listed-extension files via the attachment path built from the archive JSON in the `@apostrophecms/import-export` module (the `../` guard only checks tar entries, not the JSON fields)6.5 · Medium
- MalcolmCVE-2026-55676Authenticated RCE via unrestricted `.php` upload in the file-upload component (empty allowlist)8.8 · High
- CronicleCVE-2026-55562Stored XSS in the `full_name` field of the Activity Log → code execution in the admin session9.0 · Critical
- TautulliCVE-2026-45381Reflected XSS in the `/search` `query` parameter (incomplete escaping) → API key theft7.4 · High
- GraylogCVE-2026-69190Manager-to-Owner privilege escalation via the `share_request` field of `PUT /api/views/{id}` (the update path checks `view:edit` instead of ownership) → deletion of other users' dashboards6.3 · Medium
- SurrealDBnot requestedAuthenticated path traversal via an analyzer `mapper` filter (arbitrary file read)7.7 · High
- Kanidmnot requestedAnonymous stack-overflow crash via deeply nested LDAP filter on LDAPS7.5 · High
- SemaphoreCVE-2026-73293Privilege escalation from `manager` to `owner` via a custom-role slug collision (resolver ignores the project id, `ValidateRole` has no blocklist and no permission ceiling)8.8 · High
- UnleashCVE-2026-63462Unauthenticated denial of service via deeply nested JSON to OpenAPI-validated endpoints (unguarded `JSON.stringify` → `RangeError`, process crash)7.5 · High
- Apache AirflowCVE-2026-58076Remote code execution in the Scheduler and the API server via an unchecked `import_string()` on the class name of an exception node in Dag deserialization (`executor_config` reaches the branch)8.8 · High
- Part-DBCVE-2026-54630Authenticated RCE via `.phar` file upload from `public/media`9.6 · Critical
- TypebotCVE-2026-62862Account takeover by anonymous brute-force of the six-digit magic-link login code (no rate limit, no lockout on the verify endpoint)9.1 · Critical
- TypebotCVE-2026-62865Arbitrary server file read via the Send Email block attachment path (missing `disableFileAccess`/`disableUrlAccess` options)7.7 · High
Coordinated Disclosure
turingpoint follows the principle of coordinated disclosure: vulnerabilities we find are first reported confidentially to the affected vendor and only documented publicly once a patch is available. This gives users the opportunity to secure their systems before technical details become known.
This Expertise for Your Software
Our team finds critical vulnerabilities in production software before attackers do. Have your applications tested by the same specialists, with a penetration test from turingpoint.
