{
  "append_only": true,
  "archive_index_url": "https://vuln.signal-radar.com/data/vuln/archive/index.json",
  "archive_version": "v0.1",
  "generated_at": "2026-08-10T10:51:21.063429+00:00",
  "immutable_run": true,
  "item_count": 20,
  "items": [
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18574/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.59256,
      "epss_score": 0.00991,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18574",
      "impact_tags": [
        "authentication boundary review",
        "remote exposure relevant"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18574.json",
      "product": null,
      "public_safe_summary": "NVD: An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the... NVD: Successful exploitation could result in full compromise of the Security Management system. NVD: Check Point discovered this issue internally and has no indication of active exploitation.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18574.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review · remote exposure. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the... NVD: Successful exploitation could result in full compromise of the Security Management system. NVD: Check Point discovered this issue internally and has no indication of active exploitation.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18574/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18598/",
      "current_public_safe_latest": true,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.74285,
      "epss_score": 0.01652,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18598",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18598.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. NVD: The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. NVD: The manipulation of the argument module results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18598.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. NVD: The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. NVD: The manipulation of the argument module results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18598/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18599/",
      "current_public_safe_latest": true,
      "cvss_score": 7.3,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.69845,
      "epss_score": 0.01397,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18599",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18599.json",
      "product": null,
      "public_safe_summary": "NVD: A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. NVD: This manipulation of the argument record_size causes command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18599.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. NVD: This manipulation of the argument record_size causes command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18599/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-2346/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.20649,
      "epss_score": 0.00285,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-2346",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-2346.json",
      "product": null,
      "public_safe_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. NVD: Mobile App allows Software Integrity Attack. NVD: This issue affects Mobile App: through 12.05.2026.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-2346.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. NVD: Mobile App allows Software Integrity Attack. NVD: This issue affects Mobile App: through 12.05.2026.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-2346/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56608/",
      "current_public_safe_latest": true,
      "cvss_score": 3.7,
      "cvss_severity": "LOW",
      "epss_percentile": 0.05925,
      "epss_score": 0.00163,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-56608",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-56608.json",
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl is affected by Missing Access Control vulnerability. NVD: The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-56608.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 3.2.0",
      "source_published_impact": "This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl is affected by Missing Access Control vulnerability. NVD: The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56608/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "hcltech / icontrol",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-56609/",
      "current_public_safe_latest": true,
      "cvss_score": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.00861,
      "epss_score": 0.00097,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-56609",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-56609.json",
      "product": "icontrol",
      "public_safe_summary": "NVD: HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. NVD: It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. NVD: These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-56609.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: hcltech / icontrol; affected version context: 3.2.0",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. NVD: It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. NVD: These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-56609/timeline.json",
      "vendor": "hcltech"
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18089/",
      "current_public_safe_latest": true,
      "cvss_score": 7.5,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.07184,
      "epss_score": 0.00175,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18089",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18089.json",
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. NVD: verify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored... NVD: Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18089.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. NVD: verify_xml in Net::SAML2::Role::VerifyXML runs \"return if !$anchors && !$cacert;\" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsig:X509Certificate element, so an unanchored... NVD: Binding::POST declares cacert as an optional Maybe[Str] with no default, so a POST binding built without one takes that path, and _verify_encrypted_assertion returns early the same way with \"return $xml unless $cacert;\".",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18089/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18092/",
      "current_public_safe_latest": true,
      "cvss_score": 8.1,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.09461,
      "epss_score": 0.00196,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18092",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18092.json",
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. NVD: new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element... NVD: handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18092.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree. NVD: new_from_xml reads the NameID, attribute values, SessionIndex, audience and other identity fields with document-wide XPath, such as //saml:Assertion/saml:AttributeStatement/saml:Attribute and //saml:Subject/saml:NameID, which select the first matching element... NVD: handle_response confirms that a signature is present and, when a cacert is configured, that it chains to the CA, but XML::Sig verifies only the element named by the signature's Reference URI, so unsigned sibling assertions in the same document are not covered.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18092/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "timlegge / net\\",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18108/",
      "current_public_safe_latest": true,
      "cvss_score": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.12538,
      "epss_score": 0.0022,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18108",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18108.json",
      "product": "net\\",
      "public_safe_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. NVD: _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". NVD: The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18108.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "vendor/product: timlegge / net\\; affected version context: \\",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. NVD: _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via \"return $xml unless $xpath->exists('dsig:Signature', $assert);\". NVD: The signature check and the trust anchor check that follow run only when a signature is present, so a decrypted assertion with no dsig:Signature element reaches new_from_xml unverified and its NameID and attributes are read into the assertion object.",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18108/timeline.json",
      "vendor": "timlegge"
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18600/",
      "current_public_safe_latest": true,
      "cvss_score": 7.4,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.78597,
      "epss_score": 0.01977,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18600",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18600.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. NVD: Such manipulation of the argument switch leads to command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18600.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. NVD: Such manipulation of the argument switch leads to command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18600/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18601/",
      "current_public_safe_latest": true,
      "cvss_score": 8.9,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.82293,
      "epss_score": 0.0238,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18601",
      "impact_tags": [
        "command injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18601.json",
      "product": null,
      "public_safe_summary": "NVD: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Performing a manipulation of the argument filename results in command injection.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18601.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. NVD: This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. NVD: Performing a manipulation of the argument filename results in command injection.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18601/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-18642/",
      "current_public_safe_latest": true,
      "cvss_score": 7.8,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.03298,
      "epss_score": 0.00134,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-18642",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-18642.json",
      "product": null,
      "public_safe_summary": "NVD: Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. NVD: This issue affects eta-otp-lock: before 1.0.4.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-18642.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. NVD: This issue affects eta-otp-lock: before 1.0.4.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-18642/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-64827/",
      "current_public_safe_latest": true,
      "cvss_score": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.35838,
      "epss_score": 0.00435,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-64827",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-64827.json",
      "product": null,
      "public_safe_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from... NVD: Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-64827.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from... NVD: Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-64827/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-67608/",
      "current_public_safe_latest": true,
      "cvss_score": 8.6,
      "cvss_severity": "HIGH",
      "epss_percentile": 0.72197,
      "epss_score": 0.01522,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-67608",
      "impact_tags": [
        "command injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-67608.json",
      "product": null,
      "public_safe_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an... NVD: Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-67608.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes command injection risk · authenticated boundary. Possible impact: An attacker may be able to run unintended system commands through the affected component.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an... NVD: Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
      "sources": [
        "NVD",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-67608/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68584/",
      "current_public_safe_latest": true,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.23466,
      "epss_score": 0.00311,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68584",
      "impact_tags": [
        "authentication boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68584.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc... NVD: Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate. OSV: SiYuan before v3.7.3 Authentication Bypass via Content Endpoints",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68584.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes authentication boundary review. Possible impact: This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc... NVD: Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate. OSV: SiYuan before v3.7.3 Authentication Bypass via Content Endpoints",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68584/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68585/",
      "current_public_safe_latest": true,
      "cvss_score": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_percentile": 0.09309,
      "epss_score": 0.00194,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68585",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68585.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing. OSV: SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68585.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a block ID to retrieve the title, notebook, path, root ID, and icon of documents administrators marked as excluded from publishing. OSV: SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68585/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68586/",
      "current_public_safe_latest": true,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.1525,
      "epss_score": 0.00241,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68586",
      "impact_tags": [],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68586.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). NVD: While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. NVD: A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given...",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68586.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). NVD: While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. NVD: A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given...",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68586/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-68587/",
      "current_public_safe_latest": true,
      "cvss_score": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.15771,
      "epss_score": 0.00245,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-68587",
      "impact_tags": [
        "information exposure review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-68587.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted. OSV: SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-68587.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes information exposure review. Possible impact: An attacker may be able to access information that should not be exposed.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. NVD: Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be restricted. OSV: SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-68587/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69083/",
      "current_public_safe_latest": true,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.27732,
      "epss_score": 0.0035,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-69083",
      "impact_tags": [
        "SQL injection risk",
        "authenticated boundary review"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-69083.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. NVD: Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data. OSV: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-69083.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk · authenticated boundary. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
      "source_published_summary": "NVD: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. NVD: Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data. OSV: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69083/timeline.json",
      "vendor": null
    },
    {
      "affected_label": "-",
      "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-69084/",
      "current_public_safe_latest": true,
      "cvss_score": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_percentile": 0.21207,
      "epss_score": 0.0029,
      "first_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "id": "CVE-2026-69084",
      "impact_tags": [
        "SQL injection risk"
      ],
      "kev": false,
      "last_observed_at": "2026-08-10T10:38:36.347227+00:00",
      "latest_item_url": "https://vuln.signal-radar.com/data/vuln/items/CVE-2026-69084.json",
      "product": null,
      "public_safe_summary": "NVD: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. NVD: The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. NVD: Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded).",
      "run_item_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/items/CVE-2026-69084.json",
      "safety": {
        "auto_remediation_allowed": false,
        "exploit_detail_allowed": false,
        "external_execution_allowed": false,
        "github_issue_creation_allowed": false,
        "indexing_allowed": true,
        "noindex_removal_allowed": true,
        "noindex_required": false,
        "patch_allowed": false,
        "public_launch_allowed": true,
        "public_safe_only": true,
        "raw_source_included": false,
        "read_only": true,
        "scan_allowed": false,
        "search_console_registered": true,
        "signal_radar_integration_allowed": false
      },
      "snapshot_count": 1,
      "source_published_affected": "Affected product or version requires source confirmation.",
      "source_published_impact": "Source describes SQL injection risk. Possible impact: An attacker may be able to read or change database-backed application data.",
      "source_published_remediation": "Patch confirmed by source text; fixed version context: v3.7.3..",
      "source_published_summary": "NVD: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. NVD: The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. NVD: Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded).",
      "sources": [
        "NVD",
        "OSV",
        "Vendor Advisory"
      ],
      "timeline_url": "https://vuln.signal-radar.com/data/vuln/archive/cves/CVE-2026-69084/timeline.json",
      "vendor": null
    }
  ],
  "public_safe_only": true,
  "radar": "vuln",
  "run_id": "20260810T105121Z",
  "run_index_url": "https://vuln.signal-radar.com/data/vuln/archive/runs/20260810T105121Z/index.json",
  "safety": {
    "auto_remediation_allowed": false,
    "exploit_detail_allowed": false,
    "external_execution_allowed": false,
    "github_issue_creation_allowed": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "patch_allowed": false,
    "public_launch_allowed": true,
    "public_safe_only": true,
    "raw_source_included": false,
    "read_only": true,
    "scan_allowed": false,
    "search_console_registered": true,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1"
}