Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-92787

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/09/2026

CVE-2026-92791

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92792

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-92789

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services, enabling the server to fetch and return internal responses.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-92793

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
Gravedad CVSS v4.0: ALTA
Última modificación:
22/09/2026

CVE-2026-92785

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
24/09/2026

CVE-2026-92782

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92786

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92781

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview links with __proto__ or prototype segments to pollute Object.prototype in a visitor's browser when the SDK processes the malicious URL.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026

CVE-2026-92784

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92783

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-92774

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag information without proper authorization.
Gravedad CVSS v4.0: MEDIA
Última modificación:
24/09/2026