❌

Normal view

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

27 September 2026 at 04:16

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 26

SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >
=======================================================================
title: Local Privilege Escalation
product: Honeywell IQ MultiAccess Update Service
Β vulnerable version: IQ V27 & IQ V28
fixed version: IQ V27 SP1 & IQ V28 SP1
Β  Β  Β  Β  Β CVE number: CVE-2026-13742
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-071
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Format String (CWE-134)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-070
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-069
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...

[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-068
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...

[SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)

27 September 2026 at 04:16

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-067
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...

harness Gitspace hardcoded password for every user account

27 September 2026 at 04:14

Posted by Khashayar Fereidani on Sep 26

# harness Gitspace hardcoded password for every user account

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-gitspace-hardcoded-password-for-every-user-account
**Contact:** https://fereidani.com/contact

## Description

Gitspaces are Harness's hosted development environments: a container with
the user's source tree, running an SSH server and an IDE, with its ports
published on...

harness(gitness) registry webhook sort_order blind SQL injection

27 September 2026 at 04:14

Posted by Khashayar Fereidani on Sep 26

# harness registry webhook sort_order blind SQL injection

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-registry-webhook-sortorder-blind-sql-injection
**Contact:** https://fereidani.com/contact

## Description

Harness open source (Gitness) is a self-hosted platform for source control,
pipelines and artifact registries. The registry API lists the webhooks of a
registry at `GET...

dive tar-slip in image file extraction

27 September 2026 at 04:14

Posted by Khashayar Fereidani on Sep 26

# dive tar-slip in image file extraction

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/dive-tar-slip-in-image-file-extraction
**Contact:** https://fereidani.com/contact

## Description

dive is a terminal UI for exploring Docker image layers, and inspecting images
pulled from public registries is its main use case. The filetree view has an
extract action (the default keybinding is `ctrl+e`,...

usvg SVGZ decompression bomb in `Tree::from_data`

27 September 2026 at 04:14

Posted by Khashayar Fereidani on Sep 26

# usvg SVGZ decompression bomb in `Tree::from_data`

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-18
**Advisory:** https://fereidani.com/usvg-svgz-decompression-bomb-in-treefromdata
**Contact:** https://fereidani.com/contact

## Description

`Tree::from_data` in `crates/usvg/src/parser/mod.rs:102` detects the gzip magic
bytes at the start of the input and decompresses the data before parsing it:

```rust
//...

openEQUELLA authenticated RCE chain(s)

27 September 2026 at 04:13

Posted by evan via Fulldisclosure on Sep 26

SUMMARY: an authenticated deserialization vuln in openEQUELLA allows
an attacker to inject a SignedObject payload, unwrap the SignedObject,
create an LDAP callback and serve a JNR response to get the server to
execute arbitrary code. alongside this sink is a SSTI vuln as well.

https://blog.evan.lat/posts/openeq/

openequella is an "open source digital repository" for educational
material. it is widely used in australian universities...

[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2)

27 September 2026 at 04:12

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in Server
Technology (Legrand group) PRO3X series intelligent rack PDUs, firmware
spdu-pro3x-030600 build 46640 (ARM 32-bit uClibc Linux).

Type: authenticated listener program override leading to root command execution
(CWE-78, CWE-269; a separate hard-coded factory credential is reported as
CWE-798). PRO3X PDUs run port_mux, an inetd-style launcher that starts every
protocol...

[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)

27 September 2026 at 04:12

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in Logo
Netsis NetOpenX REST 2.0.6.9 (also distributed as Netsis Nox REST), the REST
API gateway of the Netsis enterprise ERP suite.

Type: unauthenticated SQL injection in the OAuth 2.0 token endpoint leading to
operating-system command execution via SQL Server xp_cmdshell
(CWE-89, CWE-306, CWE-78). A single POST /api/v2/token carrying no client and
no user credentials supplies a...

[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)

27 September 2026 at 04:12

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech
Conduit AEP (models mtcdt / mtcdtip / mtcdtiphp), IoT gateways running mLinux on
ARM 32-bit.

Type: authenticated OS command injection (CWE-78) through the uploaded filename
of the admin-only upload_config command. The management API is served by lighttpd
on TCP 8080 and proxied to the proprietary FastCGI daemon /usr/bin/rcell_api. The
import_config handler wraps the...

[0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1)

27 September 2026 at 04:12

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in
Lightstreamer Server 7.4.8 build 3506 (with JMS Extender 2.1.0).

Type: unauthenticated JMX inspection console allowing an anonymous caller to
invoke any MBean operation, reaching jvmtiAgentLoad on
com.sun.management:type=DiagnosticCommand to load and run a native agent
library inside the broker JVM (CWE-306, CWE-345, CWE-20, CWE-250, CWE-1188)

Scoring. This finding is...

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)

22 September 2026 at 18:32

Posted by Joe via Fulldisclosure on Sep 22

HP Advance / HP Output Central
Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file
write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084

================================================================
SUMMARY
================================================================

Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components:...

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work)

22 September 2026 at 18:31

Posted by Raschin Tavakoli via Fulldisclosure on Sep 22

nullFaktor Security Advisory < 2026-09-10 >
===========================================================
Title: Pre-Authentication Remote Code Execution in SAP
Extended Passport (EPP) processing library
Affected Components: ICM, SAP Web Dispatcher, dialog work processes

Vulnerability: Stack based Buffer Overflow
CVE: CVE-2026-44756

Impact: Critical
CVSS 4.0 Vector:...

[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
TigerGraph Community Edition 4.2.4.

Type: Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (CWE-798)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: command execution as the tigergraph service user (uid 1001), which owns the engine, graph data, catalog and
configuration tree
Authentication: unauthenticated (shipped default credentials)...

[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Teltonika RutOS 00.07.06.21.

Type: Authenticated ipsec.lua logread command injection with reflected output (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the router, with command output reflected into the JSON response
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...

APPLE-SA-09-14-2026-10 Xcode 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-10 Xcode 27

Xcode 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149040.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Xcode IDE
Available for: macOS Tahoe 26.6 and later
Impact: An app may be able to access user-sensitive data
Description: A permissions issue...
❌