VulncastBriefing archive

Daily Brief - 2026-08-24

· 4 vulnerabilities · 5 min listen

▶ Listen to this briefing

CVE-2026-10053

high · CVSS 8.5 · GitLab CE/EE

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

  • Remote Code Execution
  • Path Traversal
  • ruby
  • web application

CVE-2026-13598

RestrictMate

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

  • Broken Access Control
  • wordpress
  • php

CVE-2026-78141

high · CVSS 7.4 · Tenda CH22

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

  • Command Injection
  • router firmware

CVE-2026-78155

critical · CVSS 9.9 · StackGres Operator

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

  • Privilege Escalation
  • kubernetes
  • database management