CVE-2025-5802
- EPSS 0.25%
- Veröffentlicht 15.09.2026 09:53:53
- Zuletzt bearbeitet 18.09.2026 19:13:15
The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explic...
CVE-2026-4103
- EPSS 0.18%
- Veröffentlicht 14.09.2026 15:54:05
- Zuletzt bearbeitet 18.09.2026 19:13:15
Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered without proper encoding or neutralization. This enables the injection and execution of malicious JavaScript when affected API docum...
CVE-2026-3096
- EPSS 0.21%
- Veröffentlicht 10.09.2026 20:40:28
- Zuletzt bearbeitet 18.09.2026 19:13:15
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to exte...
CVE-2025-12737
- EPSS 0.22%
- Veröffentlicht 03.09.2026 13:02:26
- Zuletzt bearbeitet 09.09.2026 20:00:20
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploit...
CVE-2026-3416
- EPSS 0.27%
- Veröffentlicht 03.09.2026 12:35:32
- Zuletzt bearbeitet 15.09.2026 18:02:04
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated ...
CVE-2026-3415
- EPSS 0.34%
- Veröffentlicht 06.08.2026 22:17:03
- Zuletzt bearbeitet 31.08.2026 20:14:36
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML conte...
CVE-2026-3418
- EPSS 0.52%
- Veröffentlicht 06.08.2026 22:17:03
- Zuletzt bearbeitet 31.08.2026 20:14:36
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative ...
CVE-2025-6508
- EPSS 0.2%
- Veröffentlicht 06.08.2026 22:16:42
- Zuletzt bearbeitet 29.09.2026 11:10:00
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors...
- EPSS 0.39%
- Veröffentlicht 06.08.2026 22:16:41
- Zuletzt bearbeitet 29.09.2026 11:10:00
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerabil...
CVE-2024-6541
- EPSS 0.26%
- Veröffentlicht 06.08.2026 22:16:40
- Zuletzt bearbeitet 31.08.2026 20:14:36
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should...