Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82265

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress logging.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-82266

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-82267

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-82270

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82271

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82268

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed document output.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82269

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82262

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82263

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82264

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore directory to arbitrary locations accessible by the restoring user.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-82020

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82021

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
28/08/2026