In Jenkins versions 2.567 and earlier, and LTS 2.555.2 and earlier a medium severity vulnerability CVE-2026-53439 was detected. This vulnerability allows an attacker with Overall/Read permission to access sensitive user configuration data, leading to information disclosure. This occurs due to missing permission checks, which enable the attacker to determine other users’ configured timezones and enumerate the view names of other users’ “My Views”. To address this issue, users should upgrade Jenkins to a patched version 3.1.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-53439.
Read more Developer ToolsIn Prefect version 3.6.19 a high severity vulnerability CVE-2026-3514 was detected. This vulnerability allows an unauthenticated attacker to bypass authentication and gain unauthorized access to sensitive information, such as API keys and database credentials. This occurs due to the improper handling of URL path exemptions for health check probes. The authentication middleware incorrectly exempts any URL path ending with ‘health’ or ‘ready’ from authentication checks. An attacker can exploit this by creating resources (such as variables, flows, work pools, work queues, and deployments) with names ending in ‘health’ or ‘ready’ to access them without authentication. To address this issue, users should upgrade Prefect to version 3.6.22 or higher. For more details, visit https://avd.aquasec.com/nvd/2026/cve-2026-3514.
Read more Developer ToolsIn OneDev versions up to 15.0.5 a medium severity vulnerability CVE-2026-11439 was detected. This vulnerability allows a remote attacker to bypass intended access controls. This occurs due to improper authorization validation when manipulating the project.parentId argument within the Parent Project Handler for the /projects/ functionality. To address this issue, users should upgrade OneDev to version 15.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11439.
In OneDev versions up to 15.0.5 a medium severity vulnerability CVE-2026-11438 was detected. This vulnerability allows a remote attacker to bypass intended access controls. This occurs due to improper authorization validation when manipulating the project.forkedFromId argument within the /projects functionality. To address this issue, users should upgrade OneDev to version 15.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11438.
In Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 a high severity vulnerability CVE-2026-44848 was detected. This vulnerability allows a standard non-admin user with endpoint access to potentially achieve Remote Code Execution (RCE) on the host system. This occurs because the Docker plugin management endpoints (/plugins/*) lack proper authorization handler registration. As a result, standard users can bypass Resource Control access restrictions and directly call privileged operations, such as installing and enabling plugins, against the underlying Docker daemon. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8, 2.39.2, or 2.41.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44848.
Read more Developer ToolsIn Kubernetes (all versions) a medium severity vulnerability CVE-2020-8554 was detected. This vulnerability allows an attacker to intercept traffic intended for specific IP addresses, resulting in a Man-in-the-Middle (MitM) attack. This occurs because the Kubernetes API server allows users who can create a ClusterIP service to freely set the spec.externalIPs field. Additionally, an attacker with privileged access to patch the status of a LoadBalancer service can set the status.loadBalancer.ingress.ip field to achieve a similar effect. There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2020-8554.
Read more Developer ToolsIn Portainer Community Edition versions 2.33.0 to before 2.33.8 and 2.39.1 a medium severity vulnerability CVE-2026-44884 was detected. This vulnerability allows any authenticated user to read the file content of any custom template, potentially exposing sensitive environment-specific values such as connection strings, API tokens, or registry credentials. This occurs due to missing authorization checks in the Custom Template file endpoint (GET /api/custom_templates/{id}/file), enabling users to bypass Resource Control access restrictions by enumerating sequential integer IDs. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8 or 2.39.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44884.
Read more Developer ToolsIn GitLab EE versions 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 a high severity vulnerability CVE-2026-4868 was detected. This vulnerability allows an authenticated user to cause specific Duo AI workflows to run under another user’s identity. This occurs due to an authorization bypass caused by improper user identity resolution when triggering Duo AI workflow runners. To address this issue, users should upgrade GitLab EE to versions 18.10.7, 18.11.4, or 19.0.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4868.
Read more Developer ToolsIn Portainer Community Edition versions 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0 a high severity vulnerability CVE-2026-44881 was detected. This vulnerability allows an authenticated user with rights to create or update a Git-backed stack to read arbitrary files on the host filesystem that are accessible to the Portainer process. This occurs because Portainer clones Git repositories using a library that translates symlink entries into real OS symlinks without adequate validation. When the stack entry point (such as docker-compose.yml) is a symlink pointing to an arbitrary path, the API endpoint reading this file transparently follows the symlink and returns the target file’s contents in the HTTP response. To address this issue, users should upgrade Portainer Community Edition to versions 2.33.8, 2.39.2, or 2.41.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44881.
Read more Developer Tools