Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82869

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables from any workspace by supplying victim workspace identifiers in the request path while authenticating with their own workspace credentials.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82870

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently delete tables, insert arbitrary data, and modify schemas across tenant boundaries on shared instances.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82868

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.
Gravedad CVSS v4.0: MEDIA
Última modificación:
31/08/2026

CVE-2026-82859

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/08/2026

CVE-2026-82860

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/08/2026

CVE-2026-82861

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82862

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82864

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. Attackers can upload a small compressed PDF that decompresses to hundreds of megabytes, exhausting memory and crashing the Node.js process or freezing browser tabs during PDF parsing.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82858

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/08/2026

CVE-2026-82863

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.
Gravedad CVSS v4.0: ALTA
Última modificación:
31/08/2026

CVE-2026-82854

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without sanitization, allowing injection of arbitrary SMTP commands such as RCPT TO to silently add attacker-controlled recipients. Exploitation requires the application to expose the envelope size to attacker-controlled input, as Nodemailer does not include size in the default auto-constructed envelope.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/08/2026

CVE-2026-82855

Fecha de publicación:
31/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
31/08/2026