,

Vulnerability Watch No53

🔐 Kubernetes managed-serviceaccount flaw exposes cluster secrets
Operators running affected managed-serviceaccount deployments should prioritize remediation and review addon-manager ClusterRole permissions. The ability to expose cluster-wide secrets and approve arbitrary CSRs makes this a high-priority cluster security issue.
CVE-2026-75924 affects managed-serviceaccount, where a compromised addon-manager pod can use excessive ClusterRole permissions to read secrets across all namespaces and approve arbitrary Certificate Signing Requests. This could lead to information disclosure and privilege escalation within the Kubernetes cluster. The vulnerability is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD

🌐 OpenSearch Dashboards request flaw enables remote denial of service
Teams running OpenSearch Dashboards should prioritize remediation, particularly for instances reachable from untrusted networks, and follow vendor guidance for mitigation or fixes. The attack can be performed remotely with a crafted HTTP request.
CVE-2026-75897 affects the capabilities route handler in OpenSearch Dashboards, which does not bound the size of incoming request payloads. A remote attacker may send a crafted HTTP request that causes denial of service. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD

💥 Dell PowerStore SDNAS NFS flaw can enable command execution
Dell PowerStore SDNAS administrators should prioritize remediation and follow Dell guidance, especially where NFS/RPC is reachable from untrusted networks. The potential for unauthenticated remote command execution makes this particularly urgent.
CVE-2026-70415 affects Dell PowerStore SDNAS and involves a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit it for command execution or denial of service. The vulnerability is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD

🐇 RabbitMQ Java client nesting bug triggers pre-authentication crashes
Java and JVM applications using the RabbitMQ client should upgrade to 5.33.1 or later promptly, especially when connecting to brokers or network paths that are not fully trusted. The denial-of-service condition can be triggered before authentication.
CVE-2026-69220 affects the RabbitMQ Java client library prior to 5.33.1. Maliciously nested AMQP table or array values can trigger uncontrolled recursion during the pre-authentication connection.start frame, causing a StackOverflowError and denial of service. The vulnerability is rated HIGH with CVSS 8.7 and is fixed in version 5.33.1.
🔗 Read more 🔗
Source: NVD

🧠 RabbitMQ Java client flaw enables massive pre-auth memory allocation
Organizations using the RabbitMQ Java client should upgrade to 5.33.1 or later promptly. Systems connecting to untrusted brokers or across untrusted network paths deserve higher priority because the memory-exhaustion attack can occur before authentication.
CVE-2026-69219 affects the RabbitMQ Java client library prior to 5.33.1. A malicious AMQP peer can declare an extremely large field length during the pre-authentication connection.start exchange, causing an approximately 2 GB allocation, OutOfMemoryError, and potentially JVM termination. The vulnerability is rated HIGH with CVSS 8.7 and is fixed in version 5.33.1.
🔗 Read more 🔗
Source: NVD

🚨 Critical Dell PowerStore SMB flaw enables remote code execution
PowerStore SDNAS administrators should treat this as an emergency remediation priority and follow Dell guidance, especially where SMB is remotely reachable. The combination of unauthenticated access, persistent denial of service, and potential remote code execution creates severe risk.
CVE-2026-67271 is an Out-of-bounds Write vulnerability in the SMB/CIFS implementation of Dell PowerStore SDNAS. An unauthenticated remote attacker can send a specially crafted SMB packet to cause a persistent crash and, with more sophisticated exploitation, potentially achieve remote code execution. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD

☸️ Red Hat Submariner flaw can spread privileged code across clusters
Red Hat Advanced Cluster Management operators should prioritize remediation, follow vendor guidance, and tightly restrict who can modify Submariner Custom Resources. The flaw requires existing permissions, but successful abuse can enable elevated code execution across the entire cluster.
CVE-2026-66783 affects the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. A cluster administrator or another user able to modify the Submariner Custom Resource can specify an unvalidated image path and execute arbitrary code with elevated privileges across the cluster, including control-plane nodes. The vulnerability is rated HIGH with CVSS 8.2.
🔗 Read more 🔗
Source: NVD

☕ RabbitMQ Java JSON-RPC flaw can trigger attacker-chosen class initialization
Applications using RabbitMQ Java JSON-RPC functionality should upgrade to 5.33.0 or later promptly, particularly where shared brokers or network interception could let an attacker control the response. Review deployments where the JSON-RPC response path is not fully trusted.
CVE-2026-63337 affects the RabbitMQ Java client library prior to 5.33.0, specifically its JSON-RPC handling. An attacker able to supply an untrusted system.describe response can influence Class.forName with initialization enabled, potentially triggering static initializers of classes already present in the victim JVM and affecting confidentiality, integrity, and availability. The vulnerability is rated HIGH with CVSS 7.5 and is fixed in version 5.33.0.
🔗 Read more 🔗
Source: NVD

🔑 authentik flaw exposes remote-access credentials to authenticated users
Enterprise authentik users with Remote Access Control enabled should upgrade to 2026.2.6 or 2026.5.5 as appropriate and assess exposure of stored endpoint credentials. Deployments that do not use the enterprise Remote Access Control provider are not affected.
CVE-2026-61574 affects authentik enterprise deployments using the Remote Access Control provider prior to 2026.2.6 and 2026.5.5. Any authenticated user can obtain endpoint details, including stored credentials for managed RDP, SSH, and VNC targets, and may connect to systems belonging to applications they are not authorized to access. The vulnerability is rated HIGH with CVSS 8.8 and is fixed in versions 2026.2.6 and 2026.5.5.
🔗 Read more 🔗
Source: NVD

🚨 Critical authentik SAML flaw enables persistent account takeover
Administrators using affected SAML matching modes should upgrade to 2026.2.6 or 2026.5.5 immediately and review existing identity links for suspicious bindings. The issue permits full and persistent account takeover, making affected integrations an emergency remediation priority.
CVE-2026-57580 affects authentik SAML Sources using the non-default USERNAME_LINK or EMAIL_LINK matching modes prior to 2026.2.6 and 2026.5.5. An attacker who controls their NameID at the source identity provider can use an XML comment to make authentik bind the attacker’s external identity to a victim’s existing account, enabling persistent account takeover without the victim’s password or the identity provider’s private key. The vulnerability is rated CRITICAL with CVSS 9.4 and is fixed in versions 2026.2.6 and 2026.5.5.
🔗 Read more 🔗
Source: NVD

🛡️ authentik Chrome device-trust flaw lets attackers skip attestation
Enterprise authentik deployments using the Google Chrome Endpoint stage or deprecated Google Chrome Device Trust Connector should upgrade to 2026.2.6 or 2026.5.5 promptly. Risk is highest where device trust is the only additional control after primary username and password authentication.
CVE-2026-54730 affects authentik enterprise deployments using Google Chrome device-trust stages prior to 2026.2.6 and 2026.5.5. The affected stages can advance authentication without confirming that out-of-band device attestation completed, allowing an attacker to authenticate from an unverified device when device trust is relied upon. The vulnerability is rated HIGH with CVSS 8.6 and is fixed in versions 2026.2.6 and 2026.5.5.
🔗 Read more 🔗
Source: NVD

🏥 Critical ePA integration flaw enables man-in-the-middle decryption
Organizations operating affected ePA 3.x Integration deployments should upgrade to version 1.3.0 immediately. Because a network-positioned attacker can defeat server authentication and compromise sensitive medical-data traffic, this warrants emergency remediation.
CVE-2026-52723 affects ePA 3.x Integration prior to 1.3.0, where VAU server certificate validation is not anchored to independent trusted material and TLS certificate verification is disabled. A network-positioned attacker between the DiGA backend and the ePA system can impersonate the VAU server, control negotiated session keys, and read or modify encrypted VAU traffic. The vulnerability is rated CRITICAL with CVSS 9.1 and is fixed in version 1.3.0.
🔗 Read more 🔗
Source: NVD