#cwe-275

共收录 8 条相关安全情报。

← 返回所有主题
CVE-2026-75978

CVE-2026-75978 影响 xianrendzw 开发的 EasyReport 报表工具,受影响版本为 2.0.17.0522_Beta 及之前版本。漏洞位于 DataSourceController.java 文件的 DataSourceController.add 函数中,属于 QueryerFactory 组件的参数处理缺陷。攻击者可以通过构造特殊的 queryerClass 参数,导致权限校验被绕过或权限配置异常,进而产生未授权访问或操作。CVSS 评分为 6.3,攻击向量为远程网络攻击,利用复杂度低,但需要低权限账号,无需用户交互,影响范围仅限于自身组件(无作用域变化),对机密性、完整性和可用性均造成低级别影响。目前该漏洞的利用方法已公开披露,可能被攻击者用于实际攻击。厂商已通过 issue 报告获知此问题,但尚未做出回应,也没有发布补丁或缓解措施。由于 EasyReport 可能用于企业内部数据报表和敏感数据展示,若被成功利用,攻击者可能读取或修改数据源配置,导致信息泄露或系统被篡改。建议用户立即评估自身受影响情况,在官方修复前尽量限制该功能的网络暴露,并对相关接口实施访问控制或临时禁用。

💡 影响/原因: EasyReport 是常见的数据报表工具,漏洞允许低权限用户远程绕过权限检查,影响数据源配置的机密性和完整性。利用方法已公开,攻击门槛低,且厂商未回应,风险现实存在。

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-19376

CVE-2026-19376 是 Uasoft Badaso 3.0.0-alpha 版本中存在的一处权限管理漏洞。该漏洞位于组件 File API 的 src/Routes/api.php 文件中的 ApiRequest::class 函数内,攻击者可以通过远程方式利用该漏洞,导致权限问题。CVSS 评分为 7.3(高),攻击向量为网络,攻击复杂度低,无需特权或用户交互,影响机密性、完整性和可用性(均为低度)。漏洞的利用细节已被公开披露,可能被实际利用。项目方已通过 issue 报告获知此问题,但尚未做出回应。由于受影响产品为 alpha 版本,且厂商未提供修复补丁,风险较高。建议用户避免将该版本暴露在公网,限制网络访问,并密切关注官方更新,尽快升级到修复版本。目前未发现该漏洞已被在野利用的证据(KEV 未列入,在野利用标记为 False)。

💡 影响/原因: 该漏洞允许远程攻击者绕过权限限制,影响系统的机密性、完整性和可用性,且利用细节已公开,增加了被恶意利用的风险。厂商尚未修复,使用 alpha 版本的用户应尽快采取缓解措施。

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-19191

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-19190

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-12201

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-41976

Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-41978

Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-41969

Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)