Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-62208

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization. Impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Gravedad CVSS v4.0: MEDIA
Última modificación:
20/07/2026

CVE-2026-62207

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths.
Gravedad CVSS v4.0: ALTA
Última modificación:
20/07/2026

CVE-2026-62213

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-62209

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/07/2026

CVE-2026-62210

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with access to configured input paths can supply remote media URLs that consume gateway resources and reduce availability.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/07/2026

CVE-2026-62206

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform moderation actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach the affected path.
Gravedad CVSS v4.0: MEDIA
Última modificación:
20/07/2026

CVE-2026-62203

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level.
Gravedad CVSS v4.0: ALTA
Última modificación:
20/07/2026

CVE-2026-62201

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by OpenClaw policy. Attackers can send HTTP requests through the exec-server to access network resources that should have been restricted by configured policies.
Gravedad CVSS v4.0: MEDIA
Última modificación:
20/07/2026

CVE-2026-62202

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature.
Gravedad CVSS v4.0: ALTA
Última modificación:
21/07/2026

CVE-2026-62205

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perform actions that should have required a stronger authorization or policy check. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. The issue is fixed in 2026.6.6.
Gravedad CVSS v4.0: MEDIA
Última modificación:
21/07/2026

CVE-2026-2594

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitization and output escaping of uploaded image attachment titles. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was partially patched in 5.0.7.
Gravedad CVSS v3.1: MEDIA
Última modificación:
17/07/2026

CVE-2026-44251

Fecha de publicación:
17/07/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-remoted process on the manager, immediately disconnecting all agents from the manager. A second code path reached by the same underflow may allow heap memory corruption. This issue has been fixed in version 4.14.5.
Gravedad CVSS v3.1: MEDIA
Última modificación:
20/07/2026