,

Vulnerability Watch No58

👤 LeafWiki Account Update Bug Enables Role Escalation
LeafWiki administrators should update to version 0.10.1 or later and review account exposure. Restrict account creation and limit access to trusted users until patched.
CVE-2026-53527 (CVSS 8.8) is a HIGH severity vulnerability in LeafWiki versions 0.1.0 through 0.10.0. The user update API allows authenticated users to change their own account role and escalate privileges from a regular user to administrator.
🔗 Read more 🔗
Source: NVD

💥 RaTeX Parser Crash Creates Denial of Service Risk
Applications using RaTeX to render user-controlled LaTeX should update to 0.1.11 quickly. Public-facing rendering services should be treated as higher priority because malformed input can terminate the process.
CVE-2026-53530 (CVSS 8.7) is a HIGH severity vulnerability in RaTeX before version 0.1.11. A malformed UTF-8 LaTeX input can trigger a parser panic that aborts the process, causing denial of service for services rendering untrusted content.
🔗 Read more 🔗
Source: NVD

⚠️ WordPress Plugin Flaw Enables Privilege Escalation
WordPress administrators running affected WPeMatico versions should update as soon as possible. Review user accounts with access to the site because authenticated low-privilege users could abuse the flaw to elevate permissions.
CVE-2026-19883 (CVSS 8.8) is a HIGH severity vulnerability in the WPeMatico RSS Feed Fetcher plugin for WordPress. Versions up to and including 2.8.24 have a missing capability check in the wpematico_import_settings function, allowing authenticated attackers with subscriber-level access or above to update arbitrary options and potentially gain administrator access.
🔗 Read more 🔗
Source: NVD

🔑 WeeChat Authentication Timing Bug Exposes Hashes
WeeChat users running affected relay versions should upgrade to 4.9.1. Prioritize systems where relay authentication is enabled and replace affected versions with the fixed release.
CVE-2026-53525 (CVSS 7.4) is a HIGH severity vulnerability affecting WeeChat versions 0.3.1 through 4.9.0. The relay authentication process uses non-constant-time string comparisons, allowing attackers to extract server-computed hashes character by character and authenticate without knowing the password.
🔗 Read more 🔗
Source: NVD

📂 LeafWiki File Traversal Bug Can Expose Local Data
LeafWiki operators should upgrade to version 0.10.1 or later immediately. Restrict editor access and limit filesystem permissions until all instances are patched.
CVE-2026-53528 (CVSS 8.8) is a HIGH severity vulnerability in LeafWiki versions 0.3.0 through 0.10.0. An authenticated user with editor permissions can exploit path traversal in asset renaming to make sensitive local files accessible as page assets.
🔗 Read more 🔗
Source: NVD

🌐 FORT Validator Bug Threatens RPKI Route Validation
Network operators using FORT Validator should patch to version 1.6.8 quickly. This affects routing validation infrastructure, so updates should be prioritized over routine maintenance.
CVE-2026-53499 (CVSS 7.2) is a HIGH severity vulnerability affecting FORT Validator versions through 1.6.7. An RRDP processing flaw can allow cross-origin snapshot and notification URL handling that removes valid route-origin data from output, potentially enabling route hijacking or loss of reachability.
🔗 Read more 🔗
Source: NVD

🛡️ Recce Server Flaw Allows Unauthenticated SQL Execution
Recce operators should upgrade to v1.50.0 or later and avoid exposing affected servers to untrusted networks until patched. Use authentication, an authenticated reverse proxy or VPN, and least-privilege deployment as interim protections.
CVE-2026-49360 (CVSS 7.8) is a HIGH severity vulnerability in Recce versions before 1.50.0. OSS server deployments exposed to an untrusted network without authentication can allow unauthenticated SQL execution through the query run API, with possible file access impacts through DuckDB filesystem primitives.
🔗 Read more 🔗
Source: NVD

🔄 Arc Replication Validation Gap Risks Cluster Integrity
Arc Enterprise administrators should patch to 2026.06.1 and restrict cluster network access until then. Audit replication activity if unexpected MsgReplicateSync traffic is observed.
CVE-2026-48106 (CVSS 8.3) is a HIGH severity vulnerability in Arc Enterprise before version 26.06.1. The cluster replication receiver validates only the wire-format envelope and does not provide application-layer authentication for replication payloads, leaving message tampering or replay possible once a peer is on the cluster network.
🔗 Read more 🔗
Source: NVD

📁 Arc Database Path Validation Bug Exposes Storage Risks
Arc operators should upgrade to 2026.06.1 and review cluster manifests for unexpected paths. Restricting cluster network access is a useful temporary mitigation until patching is complete.
CVE-2026-48105 (CVSS 8.3) is a HIGH severity vulnerability in Arc Enterprise before version 26.06.1. The Raft FSM accepts attacker-chosen file paths in manifest-registration proposals without validating them against the configured storage backend, creating path manipulation risks.
🔗 Read more 🔗
Source: NVD

🔍 Arc Debug Endpoint Exposure Bypasses Authentication
Arc deployments should patch immediately and block /debug/pprof endpoints if updates cannot be applied. Restrict access to Arc API interfaces until the fix is deployed.
CVE-2026-48050 (CVSS 8.8) is a HIGH severity vulnerability in Arc versions before 26.06.1. The /debug/pprof endpoints can be reached without authentication because the auth middleware bypasses token checks for matching public prefixes.
🔗 Read more 🔗
Source: NVD

🧮 Arc SQL Validation Weakness Enables Unsafe File Access
Arc administrators should upgrade and restrict API access until fixed. Review SQL access controls and apply the recommended network mitigations if patching is delayed.
CVE-2026-47735 (CVSS 7.1) is a HIGH severity vulnerability in Arc before version 26.06.1. Weak SQL validation allowed DuckDB file-related functions to bypass restrictions and access files outside intended controls.
🔗 Read more 🔗
Source: NVD

🔐 iTop OQL Access Control Check Has Coverage Gap
iTop administrators should update to version 3.2.3 or later. Prioritize systems that rely on OQL queries with silo access controls.
CVE-2026-34948 (CVSS 7.7) is a HIGH severity vulnerability affecting Combodo iTop before version 3.2.3. The OQL silos access check only protects classes present in the SELECT clause, and the issue is fixed in version 3.2.3.
🔗 Read more 🔗
Source: NVD