CWE-488

CWE-488 · 4 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-488, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-103869

    A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can poi…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-103868

    A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.3CVE-2026-103544public PoC

    A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation resu…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-82806

    Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the …

    AI risk analysis on Exploit-DB.ai →