❌

Reading view

SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742

Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Sep 26

SEC Consult Vulnerability Lab Security Advisory < 20260923-0 >
=======================================================================
title: Local Privilege Escalation
product: Honeywell IQ MultiAccess Update Service
Β vulnerable version: IQ V27 & IQ V28
fixed version: IQ V27 SP1 & IQ V28 SP1
Β  Β  Β  Β  Β CVE number: CVE-2026-13742
Β  Β  Β  Β  Β  Β  Β impact: high
homepage:...
  •  

[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-071
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Format String (CWE-134)
Risk Level: Medium
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  

[SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-070
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  

[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-069
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Integer Overflow (CWE-190)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned
Author of...
  •  

[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-068
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...
  •  

[SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)

Posted by Matthias Deeg via Fulldisclosure on Sep 26

Advisory ID: SYSS-2026-067
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...
  •  

harness Gitspace hardcoded password for every user account

Posted by Khashayar Fereidani on Sep 26

# harness Gitspace hardcoded password for every user account

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-gitspace-hardcoded-password-for-every-user-account
**Contact:** https://fereidani.com/contact

## Description

Gitspaces are Harness's hosted development environments: a container with
the user's source tree, running an SSH server and an IDE, with its ports
published on...
  •  

harness(gitness) registry webhook sort_order blind SQL injection

Posted by Khashayar Fereidani on Sep 26

# harness registry webhook sort_order blind SQL injection

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/harness-registry-webhook-sortorder-blind-sql-injection
**Contact:** https://fereidani.com/contact

## Description

Harness open source (Gitness) is a self-hosted platform for source control,
pipelines and artifact registries. The registry API lists the webhooks of a
registry at `GET...
  •  

dive tar-slip in image file extraction

Posted by Khashayar Fereidani on Sep 26

# dive tar-slip in image file extraction

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-24
**Advisory:** https://fereidani.com/dive-tar-slip-in-image-file-extraction
**Contact:** https://fereidani.com/contact

## Description

dive is a terminal UI for exploring Docker image layers, and inspecting images
pulled from public registries is its main use case. The filetree view has an
extract action (the default keybinding is `ctrl+e`,...
  •  

usvg SVGZ decompression bomb in `Tree::from_data`

Posted by Khashayar Fereidani on Sep 26

# usvg SVGZ decompression bomb in `Tree::from_data`

**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-18
**Advisory:** https://fereidani.com/usvg-svgz-decompression-bomb-in-treefromdata
**Contact:** https://fereidani.com/contact

## Description

`Tree::from_data` in `crates/usvg/src/parser/mod.rs:102` detects the gzip magic
bytes at the start of the input and decompresses the data before parsing it:

```rust
//...
  •  

openEQUELLA authenticated RCE chain(s)

Posted by evan via Fulldisclosure on Sep 26

SUMMARY: an authenticated deserialization vuln in openEQUELLA allows
an attacker to inject a SignedObject payload, unwrap the SignedObject,
create an LDAP callback and serve a JNR response to get the server to
execute arbitrary code. alongside this sink is a SSTI vuln as well.

https://blog.evan.lat/posts/openeq/

openequella is an "open source digital repository" for educational
material. it is widely used in australian universities...
  •  

[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2)

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in Server
Technology (Legrand group) PRO3X series intelligent rack PDUs, firmware
spdu-pro3x-030600 build 46640 (ARM 32-bit uClibc Linux).

Type: authenticated listener program override leading to root command execution
(CWE-78, CWE-269; a separate hard-coded factory credential is reported as
CWE-798). PRO3X PDUs run port_mux, an inetd-style launcher that starts every
protocol...
  •  

[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in Logo
Netsis NetOpenX REST 2.0.6.9 (also distributed as Netsis Nox REST), the REST
API gateway of the Netsis enterprise ERP suite.

Type: unauthenticated SQL injection in the OAuth 2.0 token endpoint leading to
operating-system command execution via SQL Server xp_cmdshell
(CWE-89, CWE-306, CWE-78). A single POST /api/v2/token carrying no client and
no user credentials supplies a...
  •  

[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech
Conduit AEP (models mtcdt / mtcdtip / mtcdtiphp), IoT gateways running mLinux on
ARM 32-bit.

Type: authenticated OS command injection (CWE-78) through the uploaded filename
of the admin-only upload_config command. The management API is served by lighttpd
on TCP 8080 and proxied to the proprietary FastCGI daemon /usr/bin/rcell_api. The
import_config handler wraps the...
  •  

[0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1)

Posted by disclosure via Fulldisclosure on Sep 26

0day Rubbish Research Team is publicly disclosing a vulnerability in
Lightstreamer Server 7.4.8 build 3506 (with JMS Extender 2.1.0).

Type: unauthenticated JMX inspection console allowing an anonymous caller to
invoke any MBean operation, reaching jvmtiAgentLoad on
com.sun.management:type=DiagnosticCommand to load and run a native agent
library inside the broker JVM (CWE-306, CWE-345, CWE-20, CWE-250, CWE-1188)

Scoring. This finding is...
  •  
❌