Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-58399

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers. The validateToken middleware contains a service-to-service bypass for auth-user: service-brother when req.get('host').startsWith(getHostName()). Both values involved in the check can be influenced by an unauthenticated HTTP client: auth-user is a request header, and Host is also client-controlled. As a result, a remote unauthenticated attacker can send a request with crafted headers and bypass token validation before the normal legacy/JWT/OIDC validation logic runs. A fix has been implemented in v2.3.0.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026

CVE-2026-5142

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-5138

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-5135

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58035

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki.<br /> <br /> This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58034

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation CheckUser.<br /> <br /> This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue.<br /> <br /> <br /> <br /> This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-58031

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Improper Neutralization of Input During Web Page Generation (XSS or &amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Wikimedia Foundation MediaWiki.<br /> <br /> This vulnerability is associated with program files resources/src/mediawiki.Special.Apisandbox/ApiSandboxLayout.Js.<br /> <br /> <br /> <br /> This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0.
Gravedad CVSS v3.1: MEDIA
Última modificación:
09/07/2026

CVE-2026-23537

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server&amp;#39;s filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requires no credentials or special privileges, any attacker with network access to the server can potentially compromise the integrity of the system. This could lead to unauthorized system modifications, denial of service through disk exhaustion, or potential remote code execution.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
15/07/2026

CVE-2026-2891

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mitigate these potential vulnerabilities.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026

CVE-2026-14324

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Gravedad CVSS v3.1: MEDIA
Última modificación:
01/07/2026

CVE-2026-14330

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Multiple unbounded alloca() calls in the PulseAudio protocol server.
Gravedad CVSS v3.1: MEDIA
Última modificación:
01/07/2026

CVE-2026-13602

Fecha de publicación:
01/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay<br /> contain a code path that is intended for the transport of session <br /> parameters from a tab with isolated cookies (e.g. in the pretix widget) <br /> to a new tab. For this purpose, a set of session parameters is <br /> cryptographically signed and then passed to the new tab as a URL <br /> parameter. The plugins perform no further validation of the session <br /> parameters, other than the cryptographic signature being valid. This is <br /> fixed with the releases issued today by strictly validating that no <br /> session parameters outside of the scope of the respective plugin may be <br /> set.<br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer<br /> headers for outgoing links to prevent leakage of secrets in URLs. This <br /> redirect page also requires cryptographically signed parameters. <br /> Unfortunately, it uses the same key and salt for the signature as the <br /> previously mentioned feature in the payment integration plugins. A <br /> motivated attacker with access to at least one event in the backend can <br /> trick the system into cryptographically signing arbitrary content using <br /> specially crafted links. In combination with the previous issue, the <br /> attacker could use this to set and modify arbitrary parameters on their <br /> user session by injecting the signed parameters into the feature of the <br /> payment providers. This is fixed with the releases issued today by using<br /> different salts for the signature for each plugin and feature.<br /> <br /> <br /> <br /> <br /> * <br /> <br /> <br /> A third, unrelated feature in the core system is used for admin users<br /> to act on behalf of another user, mostly for debugging purposes. With <br /> being able to insert arbitrary parameters into a session, an attacker <br /> can abuse this feature to change their session from their actual user to<br /> any user in the system by guessing a valid user ID. This is fixed with<br /> the release today by requiring unguessable information to be contained <br /> in the session of the user to switch to.
Gravedad CVSS v4.0: ALTA
Última modificación:
02/07/2026