Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-82672

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Inconsistent Interpretation of HTTP Requests (&amp;#39;HTTP Request/Response Smuggling&amp;#39;) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.<br /> <br /> Mint.HTTP1.Parse.chunk_size/1 in lib/mint/http1/parse.ex stops at the first non-hexadecimal byte of a chunked response&amp;#39;s chunk-size line and returns the remainder unexamined. Mint.HTTP1.decode_body/5 in lib/mint/http1.ex then discards every byte up to the CRLF with Parse.ignore_until_crlf/1, so the accepted grammar is a run of hex digits followed by arbitrary bytes, where RFC 9112 permits only a ;-introduced chunk extension. Lines such as 5ZZZZZ and 5 9 are accepted as chunk size 5, and 0ZZZZ is accepted as the terminating chunk that ends the message body. An RFC-strict intermediary rejects such a line while Mint accepts it, so the two disagree on chunk boundaries and on where the response ends.<br /> <br /> This issue affects mint: from 0.1.0 before 1.10.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/09/2026

CVE-2026-82560

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.<br /> <br /> Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.<br /> <br /> Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted.
Gravedad CVSS v3.1: ALTA
Última modificación:
22/09/2026

CVE-2026-93999

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is still enabled before issuing a new access token. This allows an application with an existing refresh token to continue obtaining valid access tokens for a disabled client, potentially bypassing administrative access controls for resource servers that rely on offline JWT validation.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-94000

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-94001

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows a delegated administrator, who should be restricted from resetting passwords, to delete a user&amp;#39;s password credentials, resulting in the user being unable to log in.
Gravedad CVSS v3.1: MEDIA
Última modificación:
22/09/2026

CVE-2026-93986

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory references to potentially write outside the destination root, though downstream protections in the local backend currently block actual file escape.
Gravedad CVSS v4.0: BAJA
Última modificación:
22/09/2026

CVE-2026-93987

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume&amp;#39;s mountpoint as filepath.Join(drv.root, name) from the attacker-supplied `name` field of a Docker VolumeDriver.Create request without verifying that the result stays within drv.root (default /var/lib/docker-volumes/rclone), and checkMountpoint() then creates that directory with file.MkdirAll before mounting. A volume name containing enough `..` components (e.g. "../../../../../../etc") therefore resolves outside the base directory, allowing anyone able to submit a VolumeDriver.Create request to the plugin socket — normally the Docker daemon, or a workload that can request named volumes in a multi-tenant orchestration setup — to make the privileged rclone plugin process create a directory and mount a remote filesystem specified in the same request at an arbitrary host path, shadowing or disrupting system directories. The advisory notes Volume.restoreState() had the same missing validation when reloading persisted volume state. Fixed in 1.75.1.
Gravedad CVSS v4.0: MEDIA
Última modificación:
22/09/2026

CVE-2026-93981

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application&amp;#39;s origin.
Gravedad CVSS v4.0: BAJA
Última modificación:
21/09/2026

CVE-2026-93982

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-93983

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-93984

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.
Gravedad CVSS v4.0: MEDIA
Última modificación:
02/10/2026

CVE-2026-93985

Fecha de publicación:
19/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
02/10/2026