Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

P-T-I

#29327of 56,333
9.2Total CVSS
Vulnerabilities · 1
PT-2026-55794
9.2
2026-07-05
Unknown · Cve-Search · CVE-2026-59509
**Name of the Vulnerable Software and Affected Versions** cve-search (affected versions not specified) **Description** An unauthenticated improper input validation issue exists in the 'POST /fetch cve data' endpoint. A remote attacker can manipulate request parameters that control the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This flaw can expose administrative usernames and password hashes from the `mgmt users` collection, which may lead to offline password cracking and the compromise of administrative accounts. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.