Vulnerability
2 posts tagged with “Vulnerability”

CVE-2026-53609: ApostropheCMS Prototype Pollution Leads to Authorization Bypass (CVSS 9.1)
ApostropheCMS's apos.util.set() allows authenticated editors to pollute Object.prototype via patch operators, bypassing authorization on all REST API endpoints for subsequent unauthenticated requests. CVSS 9.1. Fixed in version 4.31.0.

CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)
Pterodactyl Wings exposes its entire daemon configuration through egg configuration-file templating, leaking API keys, SFTP credentials, and database connection strings. CVSS 9.9. Fixed in version 1.12.3.