In OpenWebUI versions 0.8.8 up to 0.11.0 a medium severity vulnerability CVE-2026-70490 was detected. This vulnerability allows an attacker to bypass user verification on terminal routes. To address this issue, users should upgrade OpenWebUI to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-70490.
Read more SecurityIn Wazuh versions prior to 4.14.5 a high severity vulnerability CVE-2026-28220 was detected. This vulnerability allows an authenticated actor to execute arbitrary code on the master node. To address this issue, users should upgrade Wazuh to version 4.14.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-28220.
Read more SecurityIn OpenWebUI versions before 0.10.0 a high severity vulnerability CVE-2026-59214 was detected. This vulnerability allows attackers to execute server-side code through configured tools via authenticated same-origin requests. To address this issue, users should upgrade OpenWebUI to version 0.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-59214.
Read more SecurityIn Zeek versions before 8.0.9 a high severity vulnerability CVE-2026-60109 was detected. This vulnerability allows unauthenticated remote attackers to cause a denial of service. To address this issue, users should upgrade Zeek to version 8.0.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-60109.
Read more SecurityIn Traefik versions prior to v2.11.51, v3.6.22, and v3.7.6 a critical severity vulnerability CVE-2026-54763 was detected. This vulnerability allows attackers to bypass authentication by using underscore-variant header names. To address this issue, users should upgrade Traefik to version 2.11.51 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54763.
Read more SecurityIn Traefik versions before 2.10.5 and 3.0.0-beta4 a high severity vulnerability CVE-2023-54365 was detected. This vulnerability allows a remote attacker to rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability. To address this issue, users should upgrade Traefik to version 2.10.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-54365.
Read more SecurityIn Traefik versions 3.7.0-ea.1 to before 3.7.5 a medium severity vulnerability CVE-2026-54762 was detected. This vulnerability allows an unauthenticated attacker to access backend services that were intended to be protected, leading to an authentication bypass. This occurs in the Kubernetes Ingress NGINX provider due to a fail-open behavior. When an Ingress explicitly enables BasicAuth or DigestAuth through annotations, but the referenced auth-secret cannot be resolved or parsed (e.g., it is missing, malformed, or policy-denied), Traefik logs the error and skips installing the authentication middleware, while still routing traffic to the backend service. To address this issue, users should upgrade Traefik to version 3.7.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54762.
In authentik versions prior to 2025.12.6, 2026.2.4, and 2026.5.1 a high severity vulnerability CVE-2026-49443 was detected. This vulnerability allows an attacker to log into any user’s account (Account Takeover). This occurs because an attacker who has the ability to change a source connection and possesses an account in one of the configured sources can exploit improper validation of the source connection to bypass authentication. To address this issue, users should upgrade authentik to versions 2025.12.6, 2026.2.4, or 2026.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-4944.
Read more SecurityIn authentik versions prior to 2025.12.5 and 2026.2.3 a medium severity vulnerability CVE-2026-41577 was detected. This vulnerability allows an attacker to replay expired SAML assertions or use assertions intended for other service providers, potentially leading to unauthorized access. This occurs because the SAML source response processor (ResponseProcessor.parse()) fails to validate the Conditions element on assertions, improperly ignoring the NotBefore, NotOnOrAfter, and AudienceRestriction restrictions. To address this issue, users should upgrade authentik to versions 2025.12.5 or 2026.2.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-41577.
Read more Security