Unknown · Cve-Search · CVE-2026-59509
**Name of the Vulnerable Software and Affected Versions**
cve-search (affected versions not specified)
**Description**
An unauthenticated improper input validation issue exists in the 'POST /fetch cve data' endpoint. A remote attacker can manipulate request parameters that control the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This flaw can expose administrative usernames and password hashes from the `mgmt users` collection, which may lead to offline password cracking and the compromise of administrative accounts.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.