PT-2026-55794 · Unknown · Cve-Search
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
cve-search (affected versions not specified)
Description
An unauthenticated improper input validation issue exists in the 'POST /fetch cve data' endpoint. A remote attacker can manipulate request parameters that control the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This flaw can expose administrative usernames and password hashes from the
mgmt users collection, which may lead to offline password cracking and the compromise of administrative accounts.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cve-Search