Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18677

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional, so a dataplane presenting a tags-bound token can register with kuma.io/workload set to any value and obtain another workload's SPIFFE identity.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-18678

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection.<br /> <br /> <br /> <br /> An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act against the control plane as that user.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-19311

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Gravedad CVSS v4.0: ALTA
Última modificación:
13/08/2026

CVE-2026-18952

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/08/2026

CVE-2026-18673

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication.<br /> <br /> <br /> <br /> An attacker with network access to a data plane&amp;#39;s port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-18676

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the admin JWT and signing material.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-18675

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.<br /> <br /> <br /> <br /> The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token<br /> <br /> <br /> <br /> A single request is a transient interruption; sustaining an outage requires repeated requests.
Gravedad CVSS v4.0: MEDIA
Última modificación:
13/08/2026

CVE-2026-8667

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer role to modify certain package registry metadata without the required maintainer-level permissions due to improper authorization checks.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-7427

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to improper input validation.
Gravedad CVSS v3.1: MEDIA
Última modificación:
19/08/2026

CVE-2026-73298

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration Solution Accelerator, specifically an authenticated IDOR (Insecure Direct Object Reference) that allows users to read, write, and delete processes belonging to other authenticated users. The issue affects multiple API endpoints, where ownership checks are missing, enabling unauthorized access and modification of migration data across users within the same organization. The vulnerability is present in both process and file management APIs, and the application relies on Entra ID authentication but lacks proper authorization controls between users. Authenticated users are able to access, modify, and delete processes and files belonging to other users without proper authorization checks.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/08/2026

CVE-2026-73299

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026

CVE-2026-73300

Fecha de publicación:
12/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
12/08/2026