CWE-497

CWE-497 · 5 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-497, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-44945public PoC

    A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transit…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-27553

    A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_table_rows endpoint using a valid user cookie allowing disclosure of all user password hashes.

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-97181

    GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.3CVE-2026-84712

    A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous respon…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.3CVE-2026-95600

    Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.

    AI risk analysis on Exploit-DB.ai →