Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82267

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission checks in the /execute and /execute/{variant} handlers. Authenticated users can guess resource names to obtain internal identifiers and insert fraudulent audit log entries misrepresenting privileged operations.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-82270

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82271

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82263

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with response content returned in API responses.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82264

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore directory to arbitrary locations accessible by the restoring user.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-82262

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82020

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-82021

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-81849

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is directed to retrieve. This issue may lead to arbitrary code execution as root if specific sensitive files are overwritten.<br /> <br /> <br /> <br /> To remediate this issue, customers should upgrade amazon-ssm-agent to version 3.3.4515.0 or later.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-77939

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attackers can leverage exposed application objects including filesystem() and serializers() within the evaluation scope to read arbitrary server files and achieve conditional remote code execution if a PHP file can be placed on disk through a secondary vector.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-77586

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes the quoted identifier early, so that additional SQL text becomes part of the generated output. If an operator or automated tool later replays that generated statement against a SQL server, the additional text is executed with the privileges of that session.
Gravedad CVSS v4.0: ALTA
Última modificación:
28/08/2026

CVE-2026-77218

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the web_sys_enablePasswd_post handler copies the enbPass POST parameter into a fixed-size stack buffer without length validation, and the web_sys_localUser_post handler copies the usrName and usrPass POST parameters into fixed-size stack buffers without length validation. A remote authenticated attacker can send a crafted request to crash the CGI process or web management service, resulting in denial of service.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026