- CVE-2026-101065 CRITICAL CVSS 9.3 -
NVD: Obot is an open-source AI agent/MCP platform. NVD: In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. NVD: When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who can reach the exposed port obtains full administrative access to the Obot API and UI, including the...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.3 (CRITICAL); EPSS percentile 36; sources: NVD.
- CVE-2026-101090 CRITICAL CVSS 9.3 -
NVD: Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. NVD: When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured... NVD: An attacker who induces a victim to begin OAuth2 login via a request that reaches Nezha with a forged Host header can cause an attacker-controlled callback URL to be used as the redirect_uri; if the OAuth2 provider accepts it, the victim's authorization code...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.3 (CRITICAL); EPSS percentile 27; sources: NVD, OSV.
- CVE-2026-101084 CRITICAL CVSS 9.3 -
NVD: obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. NVD: Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials. OSV: obot before v0.21.1 Authorization Bypass via /mcp-connect
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 9.3 (CRITICAL); EPSS percentile 18; sources: NVD, OSV.
- CVE-2026-101062 HIGH CVSS 8.7 -
NVD: Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. NVD: Because the authorization flow auto-completes for an already logged-in user with no consent screen, an attacker who registers a client pointing at their own domain and induces a logged-in victim to visit a single crafted authorization URL receives an... NVD: The token minted by the MCP OAuth flow carries the victim's full group set in the JWT, and Obot validated only the issuer and not the audience, so the token is accepted as a bearer token against any Obot API endpoint the victim can access rather than being...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 8.7 (HIGH); EPSS percentile 25; sources: NVD, OSV.
- CVE-2026-101064 HIGH CVSS 8.3 -
NVD: Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged users to specify arbitrary URLs without destination validation. NVD: Attackers with Power User or higher roles can coerce Obot to make requests to internal services and cloud metadata endpoints, reading responses in error messages to disclose sensitive credentials. OSV: Obot before v0.23.0 Server-Side Request Forgery via MCP
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.3 (HIGH); EPSS percentile 14; sources: NVD, OSV.
- CVE-2026-101086 HIGH CVSS 7.1 -
NVD: Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. NVD: Attackers can deliver command execution or Agent configuration tasks to Agents within their authorization scope by exploiting the shared protobuf Task.Type namespace between service monitors and privileged operations. OSV: Nezha Dashboard before 2.3.5 Task Type Validation Bypass
An attacker may be able to run code or commands on affected systems; CVSS 7.1 (HIGH); EPSS percentile 23; sources: NVD, OSV.
- CVE-2026-101085 HIGH CVSS 7.1 -
NVD: Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create malformed rules that trigger unrecovered panics in the alert evaluator goroutine. NVD: Attackers can submit a crafted alert rule via the POST /api/v1/alert-rule endpoint to crash the dashboard process, which persists the rule and causes repeated crashes on restart, disabling all monitoring and control plane functionality. OSV: Nezha before 2.3.8 Denial of Service via Alert Rule
The affected service may become unavailable or unreliable; CVSS 7.1 (HIGH); EPSS percentile 15; sources: NVD, OSV.
- CVE-2026-101063 MEDIUM CVSS 6.9 -
NVD: Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is enabled. NVD: Unauthenticated attackers can read registry metadata including server names, descriptions, repository URLs, and connect URLs by sending GET requests to /v0.1/servers. OSV: Obot before v0.23.0 Authentication Bypass via Registry API
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary; CVSS 6.9 (MEDIUM); EPSS percentile 14; sources: NVD, OSV.
- CVE-2026-96279 MEDIUM CVSS 6.5 -
NVD: A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. NVD: For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
An attacker may gain root or administrative-level privileges on affected systems; CVSS 6.5 (MEDIUM); EPSS percentile 48; sources: NVD.
- CVE-2026-101088 MEDIUM CVSS 6.0 -
NVD: Nezha is a server and website monitoring tool. NVD: In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/servicesentinel.go) contains an incomplete fix for a previously reported nil dereference denial of service (GHSA-qjpp-gffx-2wm9). NVD: The 2026-07-21 fix re-validated the service lifecycle under serviceResponseDataStoreLock but reused an already-captured, now stale reporter pointer and never re-validated the server, and that lock does not guard ServerShared.
The affected service may become unavailable or unreliable; CVSS 6.0 (MEDIUM); EPSS percentile 7; sources: NVD, OSV.
- CVE-2026-100875 MEDIUM CVSS 5.5 -
NVD: A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: This impacts an unknown function of the file updatedetailsfromfaculty.php. NVD: Such manipulation of the argument myfid leads to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 5.5 (MEDIUM); EPSS percentile 15; sources: NVD.
- CVE-2026-100874 MEDIUM CVSS 5.5 -
NVD: A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: This affects an unknown function of the file addnewstudent.php. NVD: This manipulation causes sql injection.
An attacker may be able to read or change database-backed application data; CVSS 5.5 (MEDIUM); EPSS percentile 15; sources: NVD.
- CVE-2026-101087 MEDIUM CVSS 5.3 -
NVD: Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but the denylist did not cover IPv6 transition ranges — specifically the 6to4 prefix 2002::/16 and the local-use IPv4/IPv6... NVD: Because such addresses satisfy Go's netip.Addr.IsGlobalUnicast check, the URL validator accepted them. NVD: An authenticated user able to configure a webhook may be able to cause the dashboard to issue requests to an otherwise restricted IPv6 endpoint, but only where the dashboard's network provides unusual or non-standards-compliant routing for these transition...
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 5.3 (MEDIUM); EPSS percentile 16; sources: NVD, OSV.
- CVE-2026-101089 LOW CVSS 2.3 -
NVD: Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. NVD: Attackers can extract password hashes and perform offline cracking attacks without rate limiting or audit trail constraints. OSV: Nezha before 2.2.7 Information Disclosure via /api/v1/profile
An attacker may be able to access information that should not be exposed; CVSS 2.3 (LOW); EPSS percentile 4; sources: NVD, OSV.
- CVE-2026-100876 LOW CVSS 2.1 -
NVD: A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: Affected is an unknown function of the file loginlinkstudent.php. NVD: Performing a manipulation of the argument umail results in missing authentication.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 18; sources: NVD.
- CVE-2026-100877 LOW CVSS 2.1 -
NVD: A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: Affected by this vulnerability is an unknown functionality of the file registrationform.php. NVD: Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 2.1 (LOW); EPSS percentile 17; sources: NVD.
- CVE-2026-100873 LOW CVSS 2.1 -
NVD: A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: The impacted element is an unknown function. NVD: The manipulation results in cross-site request forgery.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 10; sources: NVD.
- CVE-2026-100878 LOW CVSS 2.1 -
NVD: A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. NVD: Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole Endpoint. NVD: The manipulation of the argument userId/roleIds leads to authorization bypass.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 10; sources: NVD.
- CVE-2026-100879 LOW CVSS 2.1 -
NVD: A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. NVD: This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. NVD: The manipulation results in missing authorization.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 9; sources: NVD.
- CVE-2026-100880 LOW CVSS 2.0 -
NVD: A weakness has been identified in zhistaredu StarTraining up to 3.8.1. NVD: This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload Endpoint. NVD: This manipulation of the argument File causes cross site scripting.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 2.0 (LOW); EPSS percentile 8; sources: NVD.