< ciso
brief />
Tag Banner

All news with #broken access control tag

25 articles

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

SafePal order-tracking flaw exposed customer data

🔒 SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed names, emails, shipping addresses, phone numbers, and purchase details for about 39,798 customers. The company said no wallet credentials or payment card data were included and that affected customers were notified on August 16. SafePal fixed the flaw, reduced retention, purged affected records from active servers, and engaged an independent firm to validate fixes and review systems.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Adobe Commerce flaw exploited to hijack customer accounts

🔒 Adobe patched a critical incorrect-authorization vulnerability (CVE-2026-71362) in its Commerce and Magento platforms after researchers observed exploitation attempts that can let attackers switch customer sessions and access private data. Sansec's Shield WAF reportedly blocked attacks and found the flaw required no account, admin rights, or user interaction. Administrators are urged to apply the August 2026 isolated patches after ensuring the correct -p release is installed.
read more →

Cisco releases critical SD‑WAN and IOS XE fixes

🔒 Cisco issued patches for multiple critical vulnerabilities in Catalyst SD‑WAN and IOS XE Software discovered during an internal security review. The flaws—ranging from improper input validation and access control to command injection—affect many releases and have been fixed across several patched versions. Cisco noted these were found during testing, including use of frontier AI models, and are not known to be actively exploited, urging customers to update promptly.
read more →

RabbitMQ flaws risk OAuth secret exposure

🔒 Cybersecurity researchers disclosed two access-control flaws in RabbitMQ that could leak OAuth client secrets and allow cross-tenant data access. Miggo's team reported one issue exposes the broker's OAuth secret to unauthenticated requests, enabling full broker takeover, while the other permits authenticated users to read other tenants' queue metadata. Affected releases begin at 3.13.0; fixes are available in recent patch releases and administrators are urged to rotate secrets and restrict management access.
read more →

PavilionX Missing Authorization Vulnerability Adviso

🔒 A security issue was identified in Rockwell Automation FactoryTalk Analytics PavilionX due to improper authorization enforcement in API endpoints, allowing unauthorized actors to perform privileged operations such as user and role management. Rockwell Automation recommends updating PavilionX to version 7.01 or later. CISA advises minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods while performing impact analysis before defensive changes.
read more →

Siemens Ruggedcom Rox Improper Access Control Flaw

⚠ The Siemens Ruggedcom Rox product contains an improper access control vulnerability in its web server JSON‑RPC interface that can allow an authenticated remote attacker to read arbitrary files on the underlying operating system with root privileges. Siemens has released updates and advises customers to upgrade to V2.17.1 or later. The issue is tracked as CWE-88 and CISA has republished the vendor advisory to increase visibility. Administrators should restrict network access and follow Siemens' operational security guidance.
read more →

Subnet Solutions PowerSYSTEM Center: Auth and CRLF Flaws

🔒 CISA reports multiple authorization flaws and a CRLF injection affecting Subnet Solutions PowerSYSTEM Center. Authenticated users with limited permissions can expose administrative data via the REST API, delete project groups, or exploit SMTPS notification handling. Subnet Solutions advises upgrading to PSC 2020 Update 29, PSC 2024 Update 2, or the PSC 2026 GA Hotfix and contacting support for assistance.
read more →

Siemens SINEC NMS Authorization Bypass Vulnerability

⚠ Siemens ProductCERT reports an authorization bypass in SINEC NMS prior to V4.0 SP3 that permits an authenticated attacker to reset the password of any user account. The vulnerability arises from improper validation of authorization when processing password reset requests. Siemens has released V4.0 SP3 to remediate the flaw and CISA republished the vendor advisory. Until systems are updated, organizations should apply network restrictions, isolate control networks, and require secure remote access.
read more →

AgentCore Starter Toolkit Grants Broad IAM God Mode

🔐 Unit 42 found the AgentCore starter toolkit auto-creates overly permissive IAM roles that grant wildcard access to Bedrock AgentCore and ECR resources. The default deployment enables an “Agent God Mode” scenario where a compromised agent can exfiltrate container images, retrieve other agents’ MemoryIDs, invoke code interpreters, and read or poison memories across an entire AWS account. AWS updated documentation to warn these roles are intended for development; Unit 42 recommends creating scoped, least-privilege roles and auditing ECR, memory, and invoke permissions.
read more →

Lloyds Bank bug exposed customers' transaction data

🔓 Lloyds Banking Group has disclosed a software glitch that briefly allowed some mobile app users to see other customers' transactions. The bank told the UK Parliament’s Treasury Committee the problem followed an overnight IT change and a defect in the design of the code used to update the API behind the app. Of 21.6 million app users, 447,936 may have been shown another user's transactions and 114,182 may have viewed transaction details during the incident. Lloyds said no full account access or customer losses were identified and that it notified regulators, including the ICO.
read more →

UK's Companies House Confirms WebFiling Security Flaw

🔒 Companies House says its WebFiling service is back after a security flaw introduced in October 2025 exposed data for about five million U.K. companies. The bug let authenticated users view other firms' dashboards — including dates of birth, residential addresses and company email addresses — by navigating back after attempting a 'file for another company' action. The agency says no passwords or identity‑verification documents were accessed, and it has reported the issue to the ICO and NCSC while investigating whether any data was accessed or changed without permission.
read more →

Companies House WebFiling Glitch Exposes Corporate Data

🛑 The UK’s Companies House has suspended its WebFiling dashboard after researchers Dan Neidle and John Hewitt revealed a simple flaw that allows an authenticated user to view another company’s dashboard by selecting “file for another company” and using the browser back button to bypass an authentication code. The weakness could expose personal and corporate details for millions of directors and, in some cases, permit unauthorized changes to registrations. The agency is investigating and directors are advised to review their filings.
read more →

Improper Access Control in Heliox EV Chargers — Patch

⚠️ Siemens has issued updates for Heliox EV chargers after identifying an improper access control vulnerability that could allow an attacker to reach unauthorized services via the charging cable. Affected models include the Heliox Flex 180 kW and Heliox Mobile DC 40 kW stations. Siemens recommends applying the provided over-the-air (OTA) updates and contacting customer support for patch rollout details. CVE-2025-27769 is rated CVSS v3.1 2.6 (Low) and categorized as CWE-923.
read more →

SolarWinds Issues Patch for Four Critical Serv-U Flaws

🔒 SolarWinds has released updates to address four critical vulnerabilities in its Serv-U file transfer software, each rated 9.1 on the CVSS scale. The flaws include a broken access control that can create a system admin (CVE-2025-40538), two type confusion bugs (CVE-2025-40539 and CVE-2025-40540), and an IDOR (CVE-2025-40541) — all capable of enabling remote code execution when exploited with administrative privileges. The issues affect Serv-U 15.5 and are fixed in Serv-U 15.5.4. SolarWinds warns Windows deployments carry medium risk because services often run under less-privileged accounts by default, and while no active exploitation has been reported, similar past defects were abused by threat actors such as Storm-0322.
read more →

Critical Serv-U RCE Flaws Extend SolarWinds Risk Profile

⚠ SolarWinds has issued four critical patches for its Serv-U managed file transfer server to remediate remote code execution and broken access-control vulnerabilities that can lead to root or other privileged account takeover. The most severe, CVE-2025-40538, can create system admin users and execute arbitrary code, while CVE-2025-40539 and CVE-2025-40540 are type confusion flaws and CVE-2025-40541 is another broken access-control issue. Organizations should treat this as a high-urgency patch event: update immediately, verify internet exposure, check logs for signs of compromise, and rotate associated credentials.
read more →

Siemens Siveillance Video: Webhooks Missing Authorization

🔒 Siemens ProductCERT reports a Missing Authorization vulnerability in the Webhooks implementation of Siveillance Video Management Servers that can allow authenticated users with read-only privileges to gain full access to the Webhooks API. Affected releases include V2023 R1–R3, V2024 R1, and V2025 builds older than the specified hotfix revisions. Siemens has published fixes and recommends updating to the listed hotfix revisions. If patching is delayed, audit role settings and limit network exposure to affected devices.
read more →

OWASP Top 10 (2025): Supply Chain and Access Risks

🔒 The OWASP Top 10 update keeps broken access control at number one while adding new categories such as software supply chain failures and mishandling of exceptional conditions. The report also flags AI-generated code risks in a “next steps” entry titled X03:2025 Inappropriate Trust in AI Generated Code. The list draws on security data covering nearly 3 million applications and a survey of 221 experts.
read more →

Auditing Salesforce Aura: Detecting Data Exposure Risks

🔍 Mandiant introduces AuraInspector, an open-source CLI to detect access-control misconfigurations in Salesforce Aura implementations. The post explains common Aura endpoint methods attackers misuse, a GraphQL technique to bypass the 2,000-record retrieval limit, and how action bulking can enumerate records. It also outlines remediation steps and security best practices to restrict Guest and authenticated user privileges.
read more →