Cyber Security Alerts
- Home
- »
- Cyber Alerts
Blueteq Cyber Alerts
Latest High & Critical Vulnerabilities
Blueteq’s Cyber Alerts keep watch so you don’t have to. We continuously monitor newly published critical and high-risk vulnerabilities, analysing emerging threats as they appear. This page provides clear visibility of the issues that matter most, helping you stay protected.
CVE ID :CVE-2026-72859 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72837 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify,...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72836 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72833 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72830 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72831 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72829 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72827 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72828 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72826 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey....Read more
Date: 2026-08-14
CVE ID :CVE-2026-72824 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72822 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72819 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72810 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72811 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and...Read more
Date: 2026-08-14
Latest Vulnerabilities
CVE ID :CVE-2026-72859 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72837 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify,...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72836 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72833 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72830 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72831 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72829 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72827 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72828 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a bare isSuperAdmin() check...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72826 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey....Read more
Date: 2026-08-14
CVE ID :CVE-2026-72824 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72822 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72819 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72810 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket...Read more
Date: 2026-08-14
CVE ID :CVE-2026-72811 Published : Aug. 14, 2026, 11:35 a.m. | 53 minutes ago Description :SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and...Read more
Date: 2026-08-14