VulncastBriefing archive

Daily Brief - 2026-07-11

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-40005

critical · CVSS 9.1 · Apache IoTDB

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

  • Path Traversal
  • database

CVE-2026-44795

high · CVSS 8.8 · Spinnaker

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3.

  • Remote Code Execution
  • Insecure Deserialization
  • web application
  • continuous delivery

CVE-2026-56688

critical · CVSS 9.1 · Dell PowerFlex Manager

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.

  • OS Command Injection
  • management software

CVE-2026-57220

high · CVSS 7.5 · RabbitMQ

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.

  • Denial of Service
  • message broker

CVE-2026-59792

critical · CVSS 9.6 · JetBrains IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

  • Path Traversal
  • Remote Code Execution
  • ide