VulncastBriefing archive

Daily Brief - 2026-08-08

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-17603

Sonatype Nexus Repository

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection. On the default H2 database backend, this could be leveraged to achieve remote code execution as the Nexus process user.

  • Remote Code Execution
  • SQL Injection
  • web application
  • database

CVE-2026-19017

medium · CVSS 6.8 · HashiCorp Consul

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.

  • Information Disclosure
  • Path Traversal
  • service mesh
  • distributed systems

CVE-2026-20338

high · CVSS 7.5 · Cisco ClamAV

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.

  • Denial Of Service
  • Memory Corruption
  • antivirus
  • software library

CVE-2026-56793

high · CVSS 7.7 · Dell OpenManage Server Administrator

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • Improper Authentication
  • server administration

CVE-2026-68823

critical · CVSS 9.1 · Microsoft Azure Confidential Ledger

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

  • Remote Code Execution
  • cloud platform