[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 20:14:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f9ad5eb5 by security tracker role at 2026-09-11T19:13:55+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -89,19 +89,19 @@ CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to validate registration
 CVE-2026-89099 (A race condition in the document value layer of MongoDB Server can all ...)
 	TODO: check
 CVE-2026-89090 (An unrecovered panic in the event stream header decoder in Amazon AWS  ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-89066 (Improper neutralization of special elements used in an OS command in t ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-89065 (Relative path traversal in the generated file manifest cleanup compone ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-89013 (Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Dolibarr
 CVE-2026-89012 (Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypas ...)
-	TODO: check
+	NOT-FOR-US: Dolibarr
 CVE-2026-89010 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-89009 (WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V2 ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-87988 (An arbitrary file access vulnerability in Mistral Vibe allows an attac ...)
 	TODO: check
 CVE-2026-87987 (An arbitrary code execution vulnerability in Mistral Vibe allows an at ...)
@@ -129,19 +129,19 @@ CVE-2026-87122
 CVE-2026-87020 (An integer overflow in a specified pitch and buffer-size computation l ...)
 	TODO: check
 CVE-2026-86813 (The MetForm WordPress plugin before 4.1.9 does not properly neutralize ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86809 (The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86793 (SGLang allows unauthenticated pickle deserialization through /update_w ...)
 	TODO: check
 CVE-2026-85979 (Affected versions of Puppet Enterprise contain a command injection vul ...)
 	TODO: check
 CVE-2026-85116 (The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootl ...)
 	TODO: check
 CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
-	TODO: check
+	NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
 	TODO: check
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
@@ -149,23 +149,23 @@ CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow
 CVE-2026-82578 (When XML batch processing is turned on and the XPath option is selecte ...)
 	TODO: check
 CVE-2026-82535 (Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scri ...)
-	TODO: check
+	NOT-FOR-US: Chamilo LMS
 CVE-2026-82215 (The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 t ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82213 (The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not veri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-81910 (Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Inj ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81909 (Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81908 (Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81861 (CWE-522: Insufficiently Protected Credentials vulnerability that could ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-80469 (An attacker may achieve arbitrary code execution on a target system by ...)
-	TODO: check
+	NOT-FOR-US: SICK AG
 CVE-2026-80462 (A vulnerability in the Chef Automate API gateway and identity validati ...)
-	TODO: check
+	NOT-FOR-US: Progress Software
 CVE-2026-7863 (Improper neutralization of special elements used in an OS command ('OS ...)
 	TODO: check
 CVE-2026-7298 (Improper neutralization of input during web page generation ('cross-si ...)
@@ -201,63 +201,63 @@ CVE-2026-71641 (An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commi
 CVE-2026-71416 (Headroom compresses data before the data reaches a large language mode ...)
 	TODO: check
 CVE-2026-70341 (Use after free in Microsoft Edge (Chromium-based) allows an authorized ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-6642 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6641 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered remote  ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Duration  ...)
 	TODO: check
 CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
 	TODO: check
 CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in Quiz And S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62139 (Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Googl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62138 (Contributor Cross Site Scripting (XSS) in Visual Composer Website Buil ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62137 (Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62136 (Unauthenticated Broken Access Control in Flexible Quantity \u2013 Meas ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62135 (Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62134 (Contributor Insecure Direct Object References (IDOR) in Starter Templa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62133 (Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62132 (Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62114 (Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62113 (Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62112 (Editor SQL Injection in Amelia <= 2.4.9 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62111 (Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 vers ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62110 (Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62109 (Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62107 (Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62106 (Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62105 (Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62103 (Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62102 (Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62089 (Missing Authorization vulnerability in Pixar Labs Master Addons for El ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-62088 (Insertion of Sensitive Information Into Sent Data vulnerability in 10u ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57843 (NetBSD contains an information disclosure vulnerability in mm_open() w ...)
 	TODO: check
 CVE-2026-57842 (NetBSD contains a use-after-free and double-free vulnerability in msg_ ...)
@@ -269,27 +269,27 @@ CVE-2026-54047 (Laci Synchroni is a decentralized mod and appearance sync server
 CVE-2026-47839 (A vulnerability allows users authenticating through a federated OIDC p ...)
 	TODO: check
 CVE-2026-3869 (CWE-303 : Incorrect Implementation of Authentication Algorithm vulnera ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-38058 (The endpoint on the iDirect iQ200 VSAT terminal returns the complete d ...)
 	TODO: check
 CVE-2026-38056 (A local privilege escalation vulnerability exists in the iDirect iQ200 ...)
 	TODO: check
 CVE-2026-27378 (Unauthenticated Broken Access Control in Deposits and Partial Payments ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-19486 (A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gem ...)
 	TODO: check
 CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow vulnerability exis ...)
 	TODO: check
 CVE-2026-18122 (Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes res ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-18061 (Improper restriction of XML external entity references in the RemoteQu ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-17037 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15710 (An information leakage vulnerability exists in the Endpoint DLP compon ...)
-	TODO: check
+	NOT-FOR-US: Netskope
 CVE-2026-15439 (The GamiPress plugin for WordPress is vulnerable to authenticated (Sub ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-11765 (Improper neutralization of argument delimiters in a command ('argument ...)
 	TODO: check
 CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which al ...)
@@ -297,7 +297,7 @@ CVE-2025-69904 (Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, wh
 CVE-2025-15679 (Under certain circumstances such as reset to factory default operation ...)
 	TODO: check
 CVE-2024-12145 (The BuddyPress plugin for WordPress is vulnerable to Insecure Direct O ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9768
 	REJECTED
 CVE-2026-9667 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server- ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9ad5eb523caf4d10da88c0d43dc8d7f75f5200b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f9ad5eb523caf4d10da88c0d43dc8d7f75f5200b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/1cb65cfe/attachment.htm>


More information about the debian-security-tracker-commits mailing list