PT-2026-107256 · Undefined · Undefined
CVE-2026-95250
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Five more CVE IDs are in. MITRE assigned CVE-2026-95248 and CVE-2026-95250 through CVE-2026-95253 to five findings we published in batch #11 — SCADA/HMI, graph analytics, document viewing and data-centre console management.
All five were found, verified and disclosed by our AI-driven research pipeline, public with full root-cause analysis and a working PoC from day one:
CVE-2026-95248 — TigerGraph Community Edition 4.2.4 (CVSS 9.8)
Ships the tigergraph/tigergraph pair with no forced rotation, and the login response itself recommends changing it. One HTTP call installs a GSQL query whose PRINT TO CSV writes a file where you say, and the query endpoint answers with no session at all — so write authorized keys and take an SSH shell into the graph analytics platform.
CVE-2026-95250 — Ecava IntegraXor IGX 16.0.701.10 (9.8, pre-auth)
The dxweb service on 8081 exposes POST /FileUpload with no authentication and a copyTo destination you control. dxmanager then reads every JSON file in the config directory and trusts https://t.co/6uYT1OpDiN without sanitization. Web SCADA HMI in manufacturing OT — unauthenticated upload to command execution.
CVE-2026-95251 — Accusoft / Apryse PrizmDoc for Java, VirtualViewer 5.22.1 (9.8)
POST /virtualviewer/AjaxServlet?action=uploadDocument takes your bytes with no cookie, no Authorization header and no credentials, and the on-disk filename comes from your filename parameter through a sanitizer that only strips path components. Upload a JSP into the served sample-documents directory and the container compiles it for you, running as uid 0.
CVE-2026-95252 — LCDS Laquis SCADA (9.8, pre-auth)
mili.exe, the web server on TCP 11234, performs no authentication check at all when no password is configured. POST /uploade.html writes any file anywhere with no content, filename or destination validation, and GET /reset.html restarts the process — also unauthenticated. The process that autoloads your DLL is the same one hosting Modbus TCP.
CVE-2026-95253 — Opengear NGCS 25.11.8 (8.8, authenticated admin to root)
POST /api/v2/pdus accepts a JSON https://t.co/ZShguS72tb with no character filter, and commands/PDUs.lua carries it into io.popen — /bin/sh -c on the console manager that sits in front of every other device in the rack. A quoting helper exists elsewhere in the same code tree; this path never calls it.
That brings the total to sixteen CVE IDs assigned to this project's research. Four of the five are pre-authentication; four score 9.8.
Full writeups + PoCs:
https://t.co/whdf9SSMaZ
#CVE #0day #RCE #infosec #cybersecurity #SCADA #ICS #TigerGraph #Opengear
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined