VulncastBriefing archive

Daily Brief - 2026-10-02

· 5 vulnerabilities · 7 min listen

▶ Listen to this briefing

CVE-2026-103494

medium · CVSS 6.6 · JetBrains YouTrack

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes

  • Privilege Escalation
  • web application

CVE-2026-104286

critical · CVSS 9.8 · Fortinet FortiMail

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

  • Path Traversal
  • email security
  • appliance

CVE-2026-12542

medium · CVSS 5.3 · The Foreman Project Foreman

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

  • Command Injection
  • ruby
  • web application

CVE-2026-57941

critical · CVSS 9.8 · Apache HTTP Server

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

  • Use After Free
  • web server

CVE-2026-82827

critical · CVSS 9.8 · Hitachi Coding Software Suite

Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.

  • Cryptographic Failure
  • software suite