Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-92780

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92775

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92776

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92779

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with binding keys containing __proto__, prototype, or constructor paths to pollute Object.prototype during rendering, affecting all subsequent objects created in the process including other tenants' renders.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92773

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the victim's repositories.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-92778

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-92763

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92765

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92770

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter secret one character at a time through response row counts.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026

CVE-2026-92771

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue false can retrieve restricted field values through the groupBy resolver that would normally be denied.
Gravedad CVSS v4.0: ALTA
Última modificación:
23/09/2026

CVE-2026-92764

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
Gravedad CVSS v4.0: MEDIA
Última modificación:
23/09/2026

CVE-2026-92759

Fecha de publicación:
16/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
Gravedad CVSS v4.0: ALTA
Última modificación:
24/09/2026